Oreilly Using - Samba
Oreilly Using - Samba
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Copyright
UsingPreface
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Audience
for This Book
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Organization
Samba's new role as a primary domain controller and domain member server, its support for the use of
Conventions Used in This Book
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
How to
Contact
Us
shared files
and
printers
from Unix clients.
Acknowledgments
Chapter 1. Learning the Samba
Section 1.1. What Is Samba?
Section 1.2. What Can Samba Do for Me?
Section 1.3. Getting Familiar with an SMB Network
Section 1.4. An Introduction to the SMB Protocol
Section 1.5. Windows Workgroups and Domains
Section 1.6. What's New in Samba 2.2?
Section 1.7. What's New in Samba 3.0?
Section 1.8. What Can Samba Do?
Section 1.9. An Overview of the Samba Distribution
Section 1.10. How Can I Get Samba?
Chapter 2. Installing Samba on a Unix System
Section 2.1. Bundled Versions
Section 2.2. Downloading the Samba Distribution
Section 2.3. Configuring Samba
Section 2.4. Compiling and Installing Samba
Section 2.5. Enabling SWAT
Section 2.6. A Basic Samba Configuration File
Section 2.7. Firewall Configuration
Section 2.8. Starting the Samba Daemons
Section 2.9. Testing the Samba Daemons
Chapter 3. Configuring Windows Clients
Section 3.1. Windows Networking Concepts
Section 3.2. Setting Up Windows 95/98/Me Computers
Section 3.3. Setting Up Windows NT 4.0 Computers
Section 3.4. Setting Up Windows 2000 Computers
TableSamba
of Contents
Section 4.7.
as a Domain Member Server
Chapter 5. Reviews
Unix Clients
Reader Reviews
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Section 6.7. Virtual Servers
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Section
6.8. Logging
Configuration
Options
the SWAT
graphical
configuration
tool.
Updated for Windows 2000, ME, and XP, the book also explores
Chapter
7.
Name
Resolution
and
Browsing
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
Section
NT/2000/XP
7.1. Nameauthentication
Resolution
and filesystem security on the host Unix system, and accessing
shared files
and
Section
7.2.printers
Browsingfrom Unix clients.
Chapter 8. Advanced Disk Shares
Section 8.1. Filesystem Differences
Section 8.2. File Permissions and Attributes on MS-DOS and Unix
Section 8.3. Windows NT/2000/XP ACLs
Section 8.4. Name Mangling and Case
Section 8.5. Locks and Oplocks
Section 8.6. Connection Scripts
Section 8.7. Microsoft Distributed Filesystems
Section 8.8. Working with NIS
Chapter 9. Users and Security
Section 9.1. Users and Groups
Section 9.2. Controlling Access to Shares
Section 9.3. Authentication of Clients
Section 9.4. Passwords
Section 9.5. Authentication with winbind
Chapter 10. Printing
Section 10.1. Sending Print Jobs to Samba
Section 10.2. Printing to Windows Printers
Chapter 11. Additional Samba Information
Section 11.1. Time Synchronization
Section 11.2. Magic Scripts
Section 11.3. Internationalization
Section 11.4. Windows Messenger Service
Section 11.5. Miscellaneous Options
Chapter 12. Troubleshooting Samba
Section 12.1. The Tool Box
Section 12.2. The Fault Tree
Tablescript
of Contents
add machine
= command
Index
add share
command = command
add userReviews
script = command
Reader Reviews
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
browsable = boolean
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
browse
list = boolean
the SWAT
graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
browseable
boolean
Samba's new role= as
a primary domain controller and domain member server, its support for the use of
Windows
case
NT/2000/XP
sensitive = boolean
authentication and filesystem security on the host Unix system, and accessing
shared files
and printers
from Unix clients.
casesignames
= boolean
change notify timeout = number
change share command = command
character set = name
client code page = name
code page directory = directory
coding system = value
comment = string
config file = filename
copy = section name
create mask = value
create mode = value
csc policy = value
deadtime = number
debug hires timestamp = boolean
debug pid = boolean
debug timestamp = boolean
debug uid = boolean
debuglevel = number
default = service name
default case = value
default devmode = boolean
default service = share name
delete printer command = command
delete readonly = boolean
delete share command = command
delete user script = command
delete veto files = boolean
Table of
Contents
domain admin
group
= user list
Reviews
domain logons
= boolean
Reader Reviews
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
force directory mode = value
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
force
directory security
mode = value
the SWAT
graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
force
group
=
value
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
force
NT/2000/XP
security modeauthentication
= value
and filesystem security on the host Unix system, and accessing
shared files
and printers
Unix clients.
force unknown
acl userfrom
= boolean
force user = value
fstype = string
getwd cache = boolean
group = value
guest account = value
guest ok = boolean
guest only = boolean
hide dot files = boolean
hide files = slash-separated list
hide local users = boolean
hide unreadable = boolean
homedir map = name
host msdfs = boolean
hosts allow = host list
hosts deny = host list
hosts equiv = filename
include = filename
inherit acls = boolean
inherit permissions = boolean
interfaces = interface list
invalid users = user list
keepalive = number
kernel oplocks = boolean
lanman auth = boolean
large readwrite = boolean
ldap admin dn = string
ldap filter = string
Table= of
Contents
local master
boolean
Index
lock dir =
directory
Reviews
lock directory
= directory
Reader Reviews
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
lprm command = command
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
machine
password
timeout = number
the SWAT
graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
magic
output
=
filename
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
magic
NT/2000/XP
script = filename
authentication and filesystem security on the host Unix system, and accessing
shared files
and
from Unix clients.
mangle
caseprinters
= boolean
mangled map = map list
mangled names = boolean
mangled stack = number
mangling char = character
mangling method = string
map archive = boolean
map hidden = boolean
map system = boolean
map to guest = value
max connections = number
max disk size = number
max log size = number
max mux = number
max open files = number
max print jobs = number
max protocol = name
max smbd processes = number
max ttl = number
max wins ttl = number
max xmit = number
message command = command
min passwd length = number
min password length = number
min print space = number
min protocol = name
min wins ttl = number
msdfs root = boolean
Table of=Contents
nt smb support
boolean
nt statusIndex
support = boolean
Reviews
null passwords
= boolean
Reader Reviews
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
passwd program = command
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
password
level =configuration
number
the SWAT
graphical
tool. Updated for Windows 2000, ME, and XP, the book also explores
password
server
=
Samba's new role as a list
primary domain controller and domain member server, its support for the use of
Windows
path
NT/2000/XP
= directory authentication and filesystem security on the host Unix system, and accessing
shared files
and printers
from Unix clients.
pid directory
= directory
posix locking = boolean
postexec = command
postscript = boolean
preexec = command
preexec close = boolean
preferred master = boolean
prefered master = boolean
preload = service list
preserve case = boolean
printable = boolean
printcap name = filename
print command = command
printer = name
printer admin = user list
printer driver = name
printer driver file = filename
printer driver location = directory
printer name = name
printing = value
print ok = boolean
private directory = directory
protocol = name
public = boolean
queuepause command = command
queueresume command = command
read bmpx = boolean
read list = list
of Contents
root dir Table
= directory
Index = directory
root directory
Reviews
root postexec
= command
Reader Reviews
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
source environment = filename
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
ssl =
boolean configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
graphical
ssl
CA
= directory
Samba's newcertDir
role as
a primary domain controller and domain member server, its support for the use of
Windows
sslNT/2000/XP
CA certFile = filename
authentication and filesystem security on the host Unix system, and accessing
shared files
and =printers
from Unix clients.
ssl ciphers
list
ssl client cert = filename
ssl client key = filename
ssl compatibility = boolean
ssl hosts = host list
ssl hosts resign = host list
ssl require clientcert = boolean
ssl require servercert = boolean
ssl server cert = filename
ssl server key = filename
ssl version = string
stat cache = boolean
stat cache size = number
status = boolean
strict allocate = boolean
strict locking = boolean
strict sync = boolean
strip dot = boolean
sync always = boolean
syslog = number
syslog only = boolean
template homedir = path
template shell = filename
time offset = number
time server = boolean
timestamp logs = boolean
total print jobs = number
unix extensions = boolean
Table
username
levelof=Contents
number
Index
username
map = filename
users = Reviews
user list
Reader Reviews
utmp = boolean
Errata
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
winbind gid = numeric range
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
winbind
separator
= character
the SWAT
graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
winbind
uid
=
numeric
range domain controller and domain member server, its support for the use of
Samba's new role as a primary
Windows
wins
NT/2000/XP
hook = command
authentication and filesystem security on the host Unix system, and accessing
shared files
and =
printers
wins proxy
boolean from Unix clients.
wins server = value
wins support = boolean
workgroup = name
writable = boolean
writeable = boolean
write cache size = number
write list = user list
write ok = boolean
write raw = boolean
Section B.2. Glossary of Configuration Value Types
Section B.3. Configuration File Variables
Appendix C. Summary of Samba Daemons and Commands
Section C.1. Samba Daemons
smbd
nmbd
winbindd
Section C.2. Samba Distribution Programs
findsmb
make_smbcodepage
make_unicodemap
net
nmblookup
pdbedit
rpcclient
rpcclient commands
smbcacls
smbclient
smbcontrol
smbgroupedit
smbmnt
smbmount
smbpasswd
smbsh
smbspool
smbstatus
Index
smbumount
testparmReviews
Reader Reviews
testprns
Errata
wbinfo
Using Samba, 2nd Edition
Appendix D. Downloading Samba with CVS
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Appendix E. Configure Options
Appendix F. Running Samba on Mac OS X Server
Publisher: O'Reilly
Section F.1. Setup Procedures
Pub Date: February 2003
Section F.2. Configuration Details
ISBN: 0-596-00256-4
Section F.3. Rolling Your Own
Pages: 556
Appendix G. GNU Free Documentation License
Slots: 1
Section G.1. GNU Free Documentation License
Colophon
Index
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Reviews
Published
by O'Reilly
Reader Reviews
& Associates, Inc., 1005 Gravenstein Highway North, Sebastopol, CA 95472.
Errata
O'Reilly
& Associates
books may be purchased for educational, business, or sales promotional use. Online
Using
Samba,
2nd Edition
editions are also available for most titles (http://safari.oreilly.com). For more information, contact our
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
corporate/institutional sales department: (800) 998-9938 or [email protected].
Publisher:
O'Reilly
Nutshell
Handbook,
the Nutshell Handbook logo, and the O'Reilly logo are registered trademarks of
O'Reilly
Pub Date:
& Associates,
February 2003Inc. Many of the designations used by manufacturers and sellers to distinguish
their products
are claimed as trademarks. Where those designations appear in this book, and O'Reilly &
ISBN: 0-596-00256-4
Associates,
Inc. was aware of a trademark claim, the designations have been printed in caps or initial
Pages: 556
caps. The
association between the image of an African ground hornbill and the topic of Samba is a
Slots: 1
trademark of O'Reilly & Associates, Inc.
While every precaution has been taken in the preparation of this book, the publisher and authors assume
no responsibility for errors or omissions, or for damages resulting from the use of the information
Using
Samba,
Second Edition is a comprehensive guide to Samba administration. This new edition covers
contained
herein.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Preface
You are reading a book about Samba, a software suite that networks Windows, Unix, and other operating
systems using Windows' native networking protocol. Samba allows Unix servers to offer Windows
networking services by matching the filesystem and networking models of Unix to those of Windows.
Table of Contents
Samba acts as a bridge between the two systems, connecting the corresponding parts of their
Index
architectures and
providing a translation wherever necessary.
Reviews
Reader
Reviewssystems as dissimilar as Windows and Unix is a complex task, which Samba
Bridging the gap
between
Errata
handles surprisingly well. To be a good Samba administrator, your abilities must parallel Samba's. For
Using
Samba,
Edition
starters,
you2nd
need
to know basic Unix system and network administration and have a good
understanding
of
Windows
filesystems
ByDavid Collier-Brown, Robert Eckstein
, Jay Ts and networking fundamentals. In addition, you need to learn how
Samba fills in the "gray area" between Unix and Windows. Once you know how everything fits together,
you'll find it easy to configure a Samba server to provide your network with reliable and highPublisher: O'Reilly
performance computational resources.
Pub Date: February 2003
ISBN:
Our job
is to0-596-00256-4
make all of that easier for you. We do this by starting out with a quick and yet
comprehensive
Pages: 556 tour of Windows networking in Chapter 1, followed by tutorially-oriented Chapter 2 and
Chapter
3, which
tell you how to set up a minimal Samba server and configure Windows clients to work
Slots:
1
with it. Most likely, you will be surprised how quickly you can complete the required tasks.
We believe that a hands-on approach is the most effective, and you can use the Samba server you build
in Chapter 2 and Chapter 3 as a test system for trying out examples that we show and describe
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
throughout the book. You can jump around from chapter to chapter if you like, but if you continue
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
sequentially from Chapter 4 onward, by the time you finish the book you will have a well-configured
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
production Samba server ready for use. All you have to do is add the appropriate support for your
Samba's new role as a primary domain controller and domain member server, its support for the use of
intended purpose as we explain how to use each feature.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
terms.
Index
Reviews
Furthermore,
we don't assume that you are an expert in Microsoft Windows. We carefully explain all the
Reader Reviews
essential concepts related to Windows networking, and we go through the Windows side of the
Errata
installation task in considerable detail, providing examples for both Windows 95/98/Me and Windows
Using Samba, 2nd Edition
NT/2000/XP, which are significantly different. For the Unix side, we give examples that work with
By
David Collier-Brown
, Robertsystems,
Eckstein, Jay
Ts as Linux, Solaris, FreeBSD, and Mac OS X.
common
Unix operating
such
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Organization
Here is a quick description of each chapter:
Chapter 1 introduces Samba and its capabilities, then describes the most important concepts of NetBIOS
and
SMB/CIFSTable
networking.
Finally, we give you a quick overview of the daemons and utilities that are
of Contents
included
in
the
Samba
distribution.
Index
Reviews
Errata
Chapter 2 covers configuring, compiling, installing, setting up, and testing the Samba server on a Unix
Reader Reviews
platform.
Using
Samba,
2nd Edition
Chapter
3 explains
how
ISBN:
0-596-00256-4
Chapter
5 describes
methods for accessing SMB shares on the network from Unix client systems.
Pages: 556
Chapter
6 gets
you up to speed on the structure of the Samba configuration file and shows you how to
Slots:
1
take control of file-sharing services.
Chapter 7 introduces name resolution, which is used to convert NetBIOS computer names into IP
addresses, and browsing, the method used in SMB networking to find what resources are being shared
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
on the network.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT
Updated foroptions,
Windows
2000,
ME,more
and advanced
XP, the book
also explores
Chapter
8 graphical
continuesconfiguration
the discussiontool.
of file-sharing
and
covers
functions
such as
Samba's
new
role
as
a
primary
domain
controller
and
domain
member
server,
its
support
fortree.
the use of
permissions, access control lists, opportunistic locks, and setting up a Distributed filesystem
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files
and printers
clients. users, introduces you to Samba security, and shows you how
Chapter
9 discusses
how from
to setUnix
up Samba
to work with encrypted and nonencrypted passwords.
Chapter 10 discusses printer setup for sharing Unix printers on the SMB network, and allowing Unix
workstations to access SMB shared printers.
Chapter 11 bundles several miscellaneous topics associated with Samba, such as configuring Samba
shares for programmers and internationalization issues.
Chapter 12 details what to do if you have problems installing Samba. This comparatively large chapter is
packed with troubleshooting hints and strategies for identifying what is going wrong.
Appendix A provides working examples of smb.conf files for use in configuring Samba for its more
common applications. You can easily modify the examples for use in a wide variety of circumstances.
Appendix B covers each option that can be used in the Samba configuration file.
Appendix C is a quick reference that covers each server daemon and tool that make up the Samba suite.
Appendix D explains how to download the latest development version of the Samba source code using
CVS.
Appendix E documents each option that can be used with the configure command before compiling the
Samba source code.
Appendix F includes directions for sharing files and printers with the Server edition of Mac OS X.
Appendix G is the copyright license under which this book is published.
Table of Contents
Filenames,
file extensions, URLs, executable files, command options, and emphasis.
Index
Constantwidth
Reviews
Reader Reviews
Samba configuration
options, computer names, user and group names, hostnames, domain names,
Errata
other code
that appears in the text, and command-line information that should be typed verbatim
Using Samba,
Edition
on the2nd
screen.
Constant
width bold
By
David Collier-Brown
, Robert Eckstein, Jay Ts
Commands that are entered by the user and new configuration options that we wish to bring to the
attention of the reader.
Pub Date: February 2003
Constant width italic
Publisher: O'Reilly
ISBN: 0-596-00256-4
Pages:
556
Replaceable
Slots: 1
How to Contact Us
We have tested and verified the information in this book to the best of our ability, but you might find that
features have changed (or even that we have made mistakes!). Please let us know about any errors you
find, as well as your suggestions for future editions, by writing to:
Table of Contents
O'Reilly Index
& Associates, Inc.
1005
Gravenstein
Highway North
Reviews
Sebastopol,
CA
95472
Reader Reviews
(800) 998-9938 (in the United States or Canada)
Errata
(707) 829-0515 (international/local)
Using Samba, 2nd Edition
(707) 829-0104 (fax)
ISBN: 0-596-00256-4
We have
a web page for this book where we list examples and any plans for future editions. You can
Pages:
access this 556
information at:
Slots: 1
http://www.oreilly.com/catalog/samba2
You can also contact Jay Ts, the lead author of this edition, through his web site at:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
http://www.jayts.com
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Acknowledgments
We thank Leon Towns-von Stauber for thoroughly researching the use of Samba on Mac OS X and writing
material that appears in Chapter 2,Chapter 5, and Chapter 10, as well as the entire Appendix F. We also
thank our technical reviewers Sam Johnston, Matthew Temple, Marty Leisner, and Don McCall.
Table of Contents
Index
Jay Ts
Reviews
Reader Reviews
Errata
This book would
have been extremely difficult to write if it hadn't been for the copy of VMware
Using Samba, 2nd Edition
Workstation graciously provided by VMware, Inc. I want to thank Rik Farrow for his clarifying comments
By
Collier-Brown
, Robert Eckstein
, Jay and
Ts Windows, and both him and Rose Moon for their supportive
onDavid
security
topics related
to Samba
friendship. Thanks also go to Mark Watson for his encouragement and advice on the topic of authoring
technical
books.
Publisher:
O'ReillyAdditionally, I'd like to express my appreciation to Andy Oram at O'Reilly for being a
supportive,
friendly, and easygoing editor, and for offering me terms that I could say yes tosomething
Pub Date: February 2003
that a few other publishers didn't even approach. SuSE, Inc. generously provided a copy of SuSE Linux
ISBN: 0-596-00256-4
8.1 Professional.
Pages: 556
Slots: 1
Robert Eckstein
I'd
firstSamba,
like to Second
recognize
DaveisCollier-Brown
and Peter
for all administration.
their help in theThis
creation
of this book.
Using
Edition
a comprehensive
guideKelly
to Samba
new edition
covers
I'd
also
like
to
thank
each
technical
reviewer
who
helped
polish
this
book
into
shape
on
such
short
notice:
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0,
as well
as
Matthew
Jeremy
Allison, and
course Andrew
Tridgell.
Andrew
andXP,
Jeremy
deserve
the SWATTemple,
graphical
configuration
tool.ofUpdated
for Windows
2000,
ME, and
the book
also special
explores
recognition,
only
creating
such acontroller
wonderfuland
product,
but
also forserver,
providing
a tirelessfor
amount
Samba's newnot
role
as for
a primary
domain
domain
member
its support
the useofof
support
in
the
final
phase
of
this
bookhats
off
to
you,
guys!
A
warm
hug
goes
out
to
my
wife
Michelle,
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
who
once
again
put
up
with
a
husband
loaded
down
with
too
much
caffeine
and
a
tight
schedule.
Thanks
shared files and printers from Unix clients.
to Dave Sifry and the people at LinuxCare, San Francisco, for hosting me on such short notice for Andrew
Tridgell's visit. And finally, a huge amount of thanks to our editor, Andy Oram, who (very) patiently
helped guide this book through its many stages until we got it right.
David Collier-Brown
I'd particularly like to thank Joyce, who put up with me during the sometimes exciting development of
the book. My thanks to Andy Oram, who was kind enough to provide the criticism that allowed me to
contribute; the crew at ACE (Opcom) who humored the obvious madman in their midst; and Ian
MacMillan, who voluntarily translated several of my early drafts from nerd to English. I would also like to
give special thanks to Perry Donham, Drew Sullivan, and Jerry DeRoo for starting and sustaining this mad
project. Finally, I'd like to thank Bob Eckstein for a final, sustained, and professional effort that lifted the
whole book up to the level that Andy needed.
All
We would especially like to give thanks to Perry Donham and Peter Kelly for helping mold the first draft of
this book. Although Perry was unable to contribute to subsequent drafts, his material was essential to
getting this book off on the right foot. In addition, some of the browsing material came from text
originally written by Dan Shearer for O'Reilly.
Table of Contents
Indexseem natural to use a Windows server to serve files and printers to a network
Although it might
Reviewsclients, there are good reasons for preferring a Samba server for this duty. Samba is
containing Windows
Reader
reliable software
thatReviews
runs on reliable Unix operating systems, resulting in fewer problems and a low cost
Errata
of maintenance.
Samba also offers better performance under heavy loads, outperforming Windows 2000
Using
Samba,
Edition
Server
by a 2nd
factor
of 2 to 1 on identical PC hardware, according to published third-party benchmarks.
When
common,
inexpensive
PC hardware
fails to meet the demands of a huge client load, the Samba
ByDavid Collier-Brown, Robert Eckstein
, Jay Ts
server can easily be moved to a proprietary "big iron" Unix mainframe, which can outperform Windows
running on a PC many times. If all that weren't enough, Samba has a very nice cost advantage: it's free.
Publisher: O'Reilly
Not only is the software itself freely available, but also no client licenses are required, and it runs on highPub Date: February 2003
quality,
free operating systems such as Linux and FreeBSD.
ISBN: 0-596-00256-4
After reading
Pages: 556
the previous paragraph, you might come to the conclusion that Samba is commonly used
by large
organizations
with thousands of users on their networksand you'd be right! But Samba's user
Slots: 1
base includes organizations all over the planet, of all types and sizes: from international corporations, to
medium and small businesses, to individuals who run Samba on their Linux laptops. In the last case, a
tool such as VMware is used to run Windows on the same computer, with Samba enabling the two
operating
systems
to share
files.
Using Samba,
Second
Edition
is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
The types of users vary even moreSamba is used by corporations, banks and other financial
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
institutions, government and military organizations, schools, public libraries, art galleries, families, and
Samba's new role as a primary domain controller and domain member server, its support for the use of
even authors! This book was developed on a Linux system running VMware and Windows 2000, with
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Adobe FrameMaker running on Windows and the document files served by Samba from the Linux
shared files and printers from Unix clients.
filesystem.
Does all this whet your technological appetite? If so, we encourage you to keep reading, learn about
Samba, and follow our examples to set up a Samba server of your own. In this and upcoming chapters,
we will tell you exactly how to get started.
Table of
Contents
Microsoft Windows
Index and appearing as another Windows system on the network from the perspective of a
Windows client.
A Samba server offers the following services:
Reviews
Reader Reviews
Errata
ByDavid
Share
Collier-Brown
one or ,more
RobertDistributed
Eckstein, Jay Ts
filesystem
(Dfs) trees
Share printers installed on the server among Windows clients on the network
Publisher: O'Reilly
Authenticate
Pages: 556
clients logging onto a Windows domain
Slots: 1
Provide or assist with Windows Internet Name Service (WINS) name-server resolution
The Samba suite also includes client tools that allow users on a Unix system to access folders and
printers that Windows systems and Samba servers offer on the network.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of brainchild
Samba from
2.0 to 2.2,
including
from
an alpha
version ofteam.
3.0, as
well as
Samba
is the
of Andrew
Tridgell,
who selected
currentlyfeatures
heads the
Samba
development
Andrew
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
started the project in 1991, while working with a Digital Equipment Corporation (DEC) software suite
Samba's
new role created
as a primary
domain controller
domain to
member
server,
its support
the use of
called
Pathworks,
for connecting
DEC VAXand
computers
computers
made
by otherfor
companies.
Windowsknowing
NT/2000/XP
authentication
and filesystem
security
on the
host aUnix
system,program
and accessing
Without
the significance
of what
he was doing,
Andrew
created
file-server
for an odd
shared files
Unix clients.
protocol
thatand
wasprinters
part of from
Pathworks.
That protocol later turned out to be SMB. A few years later, he
expanded upon his custom-made SMB server and began distributing it as a product on the Internet under
the name "SMB Server." However, Andrew couldn't keep that nameit already belonged to another
company's productso he tried the following Unix renaming approach:
$grep -i '^s.*m.*b' /usr/dict/words
And the response was:
salmonberry
samba
sawtimber
scramble
Thus, the name "Samba" was born.
Today, the Samba suite revolves around a pair of Unix daemons that provide shared resourcescalled
shares or servicesto SMB clients on the network. These are:
smbd
A daemon that handles file and printer sharing and provides authentication and authorization for
SMB clients.
nmbd
A daemon that supports NetBIOS Name Service and WINS, which is Microsoft's implementation of
a NetBIOS Name Server (NBNS). It also assists with network browsing.
Samba is currently maintained and extended by a group of volunteers under the active supervision of
Andrew Tridgell. Like the Linux operating system, Samba is distributed as open source software
(http://opensource.org) by its authors and is distributed under the GNU General Public License (GPL).
Since its inception, development of Samba has been sponsored in part by the Australian National
University, where Andrew Tridgell earned his Ph.D. Since then, many other organizations have sponsored
Samba developers, including LinuxCare, VA Linux Systems, Hewlett-Packard, and IBM. It is a true
testament to Samba that both commercial and noncommercial entities are prepared to spend money to
support an open source effort.
Microsoft has also contributed by offering its definition of the SMB protocol to the Internet Engineering
Table in
of 1996
Contents
Task Force (IETF)
as the Common Internet File System (CIFS). Although we prefer to use the
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
You don't want to pay foror can't afforda full-fledged Windows server, yet you still need the
Reviews
functionality that one provides.
Reader Reviews
Errata
The Client
Access Licenses (CALs) that Microsoft requires for each Windows client to access a
unaffordable.
Using Windows
Samba, 2ndserver
Editionare
You want to provide a common area for data or user directories to transition from a Windows server
to a Unix one, or vice versa.
Publisher: O'Reilly
Pub Date: February 2003
You
Pages:
are
556
supporting a group of computer users who have a mixture of Windows and Unix computers.
Slots: 1
You want to integrate Unix and Windows authentication, maintaining a single database of user
accounts that works with both systems.
You want to network Unix, Windows, Macintosh (OS X), and other systems using a single protocol.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
Samba
2.0 toin2.2,
including
selected
features
from
an alpha
version
of 3.0, as well as
Let's
take a of
quick
tourfrom
of Samba
action.
Assume
that we
have the
following
basic
network
the SWAT graphical
configurationUnix
tool.system,
Updatedtofor
Windows
2000,
ME,
and
XP, toltec,
the bookand
alsoa explores
configuration:
a Samba-enabled
which
we will
assign
the
name
pair of
Samba's new
roletoaswhich
a primary
domain
and
domain
member
its support
for area
the use of
Windows
clients,
we will
assigncontroller
the names
maya
and aztec,
allserver,
connected
via a local
Windows(LAN).
NT/2000/XP
authentication
filesystem
security
the host
Unix
system, and
network
Let's also
assume thatand
toltec
also has
a localoninkjet
printer
connected
to it,accessing
lp, and a
shared
filesnamed
and printers
from Unix
clients.
disk
share
spiritboth
of which
it can offer to the other two computers. A graphic of this
network is shown in Figure 1-1.
In this network, each computer listed shares the same workgroup. A workgroup is a group name tag that
identifies an arbitrary collection of computers and their resources on an SMB network. Several
workgroups can be on the network at any time, but for our basic network example, we'll have only one:
the METRAN workgroup.
see a list of all the workgroups that currently exist on the network.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
We can take a closer look at the toltec server by double-clicking its icon. This contacts toltec itself and
ISBN: 0-596-00256-4
requests a list of its sharesthe file and printer resourcesthat the computer provides. In this case, a
Pages:
556 lp, a home directory named jay, and a disk share named spirit are on the server, as
printer named
1
shown Slots:
in Figure
1-3. Note that the Windows display shows hostnames in mixed case (Toltec). Case is
irrelevant in hostnames, so you might see toltec, Toltec, and TOLTEC in various displays or command
output, but they all refer to a single system. Thanks to Samba, Windows 98 sees the Unix server as a
valid SMB server and can access the spirit folder as if it were just another system folder.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of 1-3.
SambaShares
from 2.0 available
to 2.2, including
selected
features
from an
version
of 3.0,
as well as
Figure
on the
Toltec
server
asalpha
viewed
from
maya
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
One popular Windows feature is the ability to map a drive letter (such as E:, F:, or Z:) to a shared
directory on the network using the Map Network Drive option in Windows Explorer.[1] Once you do so,
your applications can access the folder across the network using the drive letter. You can store data on it,
install and run programs from it, and even password-protect it against unwanted visitors. See Figure 1-4
for an example of mapping a drive letter to a network directory.
[1]
You can also right-click the shared resource in the Network Neighborhood and then select the Map Network Drive
menu item.
Table of Contents
Index
Reviews
Reader Reviews
\\network-computer\directory
Publisher: O'Reilly
February
2003
ThisPub
is Date:
known
as the
Universal Naming Convention (UNC) in the Windows world. For example, the dialog
box in ISBN:
Figure
0-596-00256-4
1-4 represents the network directory on the toltec server as:
Pages: 556
\\toltec\spirit
Slots: 1
If this looks somewhat familiar to you, you're probably thinking of uniform resource locators (URLs),
which are addresses that web browsers such as Netscape Navigator and Internet Explorer use to resolve
systems across the Internet. Be sure not to confuse the two: URLs such as http://www.oreilly.com use
Using
Samba,
Second
Edition
is a comprehensive
guide to the
Samba
administration.
This
newtransfer
edition covers
forward
slashes
instead
of backslashes,
and they precede
initial
slashes with the
data
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as well as
protocol (i.e., ftp, http) and a colon (:). In reality, URLs and UNCs are two completely separate things,
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
although sometimes you can specify an SMB share using a URL rather than a UNC. As a URL, the
Samba's
new share
role aswould
a primary
domain as
controller
and domain
\\toltec\spirit
be specified
smb://toltec/spirit
. member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
sharedthe
files
and printers
UnixWindows
clients. and its programs behave as if the networked directory were a
Once
network
drive isfrom
set up,
local disk. If you have any applications that support multiuser functionality on a network, you can install
those programs on the network drive.[2]Figure 1-5 shows the resulting network drive as it would appear
with other storage devices in the Windows 98 client. Note the pipeline attachment in the icon for the J:
drive; this indicates that it is a network drive rather than a fixed drive.
[2]
Be warned that many end-user license agreements forbid installing a program on a network so that multiple clients
can access it. Check the legal agreements that accompany the product to be absolutely sure.
Figure 1-5. The Network directory mapped to the client drive letter J
My Network Places, found in Windows Me, 2000, and XP, works differently from Network Neighborhood.
It is necessary to click a few more icons, but eventually we can get to the view of the toltec server as
shown in Figure 1-6. This is from a Windows 2000 system. Setting up the network drive using the Map
Network Drive option in Windows 2000 works similarly to other Windows versions.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
1.2.2 ISBN:
Sharing
a Printer
0-596-00256-4
Pages: 556
You probably noticed that the printer lp appeared under the available shares for toltec in Figure 1-3.
Slots: 1
This indicates that the Unix server has a printer that can be shared by the various SMB clients in the
workgroup. Data sent to the printer from any of the clients will be spooled on the Unix server and printed
in the order in which it is received.
Using
Second Editionprinter
is a comprehensive
guide
toisSamba
administration.
This
edition
covers
SettingSamba,
up a Samba-enabled
on the Windows
side
even easier
than setting
upnew
a disk
share.
By
all versions of Samba
fromand
2.0 identifying
to 2.2, including
selected features
from an
alpha
3.0, for
as well
double-clicking
the printer
the manufacturer
and model,
you
can version
install aof
driver
this as
the SWAT
configuration
tool. Updated
Windows
2000,
ME,
and XP, the
book
explores
printer
on graphical
the Windows
client. Windows
can thenfor
properly
format
any
information
sent
to also
the network
Samba's
new
role as
a primary
domain
and
domain98,
member
server, itsthe
support
for icon
the use
of
printer
and
access
it as
if it were
a localcontroller
printer. On
Windows
double-clicking
Printers
in the
WindowsPanel
NT/2000/XP
authentication
and shown
filesystem
security
the host
accessing
Control
opens the
Printers window
in Figure
1-7.on
Again,
noteUnix
the system,
pipeline and
attachment
below
shared
files which
and printers
from
Unix
clients.
the
printer,
identifies
it as
being
on a network.
uid
gid
Table of Contents
pid
machine
Index
----------------------------------------
Reviews
spirit
Reader
jay Reviews
jay
Errata
Using
Samba, 2nd
Edition jay
spirit
jay
7735
maya
7779
aztec
maya
jay
jay
jay
7735
Publisher: O'Reilly
Pub Date: February 2003
0-596-00256-4
LockedISBN:
files:
Pages: 556
Pid
Slots:
1
DenyMode
R/W
Oplock
Name
-------------------------------------------------7735
DENY_WRITE
/u/RegClean.exe
Sun Aug 12 13:01:22
Using Samba,
SecondRDONLY
Edition is a NONE
comprehensive
guide to Samba administration.
This new 2002
edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Share
mode
memory usage
(bytes):and filesystem security on the host Unix system, and accessing
Windows
NT/2000/XP
authentication
shared files and printers from Unix clients.
1048368(99%) free + 136(0%) used + 72(0%) overhead = 1048576(100%) total
The Samba status from this output provides three sets of data, each divided into separate sections. The
first section tells which systems have connected to the Samba server, identifying each client by its
machine name (maya and aztec) and IP (Internet Protocol) address. The second section reports the
name and status of the files that are currently in use on a share on the server, including the read/write
status and any locks on the files. Finally, Samba reports the amount of memory it has currently allocated
to the shares that it administers, including the amount actively used by the shares plus additional
overhead. (Note that this is not the same as the total amount of memory that the smbd or nmbd
processes are using.)
Don't worry if you don't understand these statistics; they will become easier to understand as you move
through the book.
of Contents
Microsoft implementations
of it, and finally we will show you where a Samba server can and cannot fit
Index
into the picture.
Reviews
Reader Reviews
Errata
To begin, let's step back in time. In 1984, IBM authored a simple application programming interface (API)
for Publisher:
networking
its computers, called the Network Basic Input/Output System (NetBIOS). The NetBIOS
O'Reilly
APIPub
provided
a
rudimentary design for an application to connect and share data with other computers.
Date: February 2003
ISBN: 0-596-00256-4
It's helpful to think of the NetBIOS API as networking extensions to the standard BIOS API calls. The
556 low-level code for performing filesystem operations on the local computer. NetBIOS
BIOS Pages:
contains
Slots:
1 to exchange instructions with computers across IBM PC or Token Ring networks. It
originally
had
therefore required a low-level transport protocol to carry its requests from one computer to the next.
In late 1985, IBM released one such protocol, which it merged with the NetBIOS API to become the
NetBIOS
Extended
User
Interface
(NetBEUI ). NetBEUI
designed
for small LANs,
it edition
let eachcovers
Using Samba,
Second
Edition
is a comprehensive
guide was
to Samba
administration.
Thisand
new
computer
claim
a
name
(up
to
15
characters)
that
wasn't
already
in
use
on
the
network.
By
a "small
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0,
as well as
LAN,"
we
mean
fewer
than
255
nodes
on
the
networkwhich
was
considered
a
generous
number
in
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
1985!
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
The
NetBEUI
protocol
was
veryUnix
popular
with networking applications, including those running under
shared
files and
printers
from
clients.
Windows for Workgroups. Later, implementations of NetBIOS over Novell's IPX networking protocols also
emerged, which competed with NetBEUI. However, the networking protocols of choice for the burgeoning
Internet community were TCP/IP and UDP/IP, and implementing the NetBIOS APIs over those protocols
soon became a necessity.
Recall that TCP/IP uses numbers to represent computer addresses (192.168.220.100, for instance) while
NetBIOS uses only names. This was a major issue when trying to mesh the two protocols together. In
1987, the IETF published standardization documents, titled RFC 1001 and 1002, that outlined how
NetBIOS would work over a TCP/UDP network. This set of documents still governs each implementation
that exists today, including those provided by Microsoft with its Windows operating systems, as well as
the Samba suite.
Since then, the standard that this document governs has become known as NetBIOS over TCP/IP, or NBT
for short.[3]
[3]
You might also see the abbreviation NetBT, which is common in Microsoft literature.
The NBT standard (RFC 1001/1002) currently outlines a trio of services on a network:
A name service
Two communication services:
Datagrams
Sessions
Thename service solves the name-to-address problem mentioned earlier; it allows each computer to
declare a specific name on the network that can be translated to a machine-readable IP address, much
like today's Domain Name System (DNS) on the Internet. The datagram and session services are both
secondary communication protocols used to transmit data back and forth from NetBIOS computers
across the network.
Tablewould
of Contents
either of them.
There are two different approaches to ensuring that this doesn't happen:
Index
Reviews
Reader Reviews
Use an NBNS to keep track of which hosts have registered a NetBIOS name.
Errata
Using Allow
Samba,each
2nd Edition
computer
on the network to defend its name in the event that another computer
ByDavid
attempts
Collier-Brown
to use
, Robert
it. Eckstein,Jay Ts
Figure
1-8 illustrates a (failed) name registration, with and without an NBNS.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
As mentioned earlier, there must be a way to resolve a NetBIOS name to a specific IP address; this is
known as name resolution. There are two different approaches with NBT here as well:
Have each computer report back its IP address when it "hears" a broadcast request for its NetBIOS
name.
Use an NBNS to help resolve NetBIOS names to IP addresses.
Figure 1-9 illustrates the two types of name resolution.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
As you might expect, having an NBNS on your network can help out tremendously. To see exactly why,
let's look at the broadcast method.
Here,
a client
computer
boots,
it will broadcast
a message
that it wishes
to register
a
Using when
Samba,
Second
Edition is
a comprehensive
guide
to Sambadeclaring
administration.
This new
edition covers
specified
NetBIOS
name
as
its
own.
If
nobody
objects
to
the
use
of
the
name,
it
keeps
the
name.
On
the
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well
as
other
hand,
if
another
computer
on
the
local
subnet
is
currently
using
the
requested
name,
it
will
send
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores a
message
backrole
to the
requesting
client that
the name
alreadymember
taken. This
is known
as defending
the of
Samba's new
as a
primary domain
controller
andisdomain
server,
its support
for the use
hostname.
This
type
of
system
comes
in
handy
when
one
client
has
unexpectedly
dropped
off
the
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
networkanother
can take
its Unix
nameclients.
unchallengedbut it does incur an inordinate amount of traffic on
shared files and printers
from
the network for something as simple as name registration.
With an NBNS, the same thing occurs, except the communication is confined to the requesting computer
and the NBNS. No broadcasting occurs when the computer wishes to register the name; the registration
message is simply sent directly from the client to the NBNS, and the NBNS replies regardless of whether
the name is already taken. This is known as point-to-point communication, and it is often beneficial on
networks with more than one subnet. This is because routers are generally configured to block incoming
packets that are broadcast to all computers in the subnet.
The same principles apply to name resolution. Without an NBNS, NetBIOS name resolution would also be
done with a broadcast mechanism. All request packets would be sent to each computer in the network,
with the hope that one computer that might be affected will respond directly back to the computer that
asked. Using an NBNS and point-to-point communication for this purpose is far less taxing on the
network than flooding the network with broadcasts for every name-resolution request.
It can be argued that broadcast packets do not cause significant problems in modern, high-bandwidth
networks of hosts with fast CPUs, if only a small number of hosts are on the network, or the demand for
bandwidth is low. There are certainly cases where this is true; however, our advice throughout this book
is to avoid relying on broadcasts as much as possible. This is a good rule to follow for large, busy
networks, and if you follow our advice when configuring a small network, your network will be able to
grow without encountering problems later on that might be difficult to diagnose.
Value
Uses broadcast registration and resolution only.
Uses point-to-point registration and resolution only.
Table of Contents
m-node
Uses broadcast for registration. If successful, it notifies the NBNS of the result. Uses
Index
(mixed)
Reader Reviews
(hybrid)
Errata
unresponsive or inoperative.
h-node
Uses the NBNS for registration and resolution; uses broadcast if the NBNS is
You can
find the node type of a Windows 95/98/Me computer by running the winipcfg command from the
ISBN: 0-596-00256-4
Start
Run dialog (or from an MS-DOS prompt) and clicking the More Info>> button. On Windows
Pages: 556
NT/2000/XP, you can use the ipconfig/all command in a command-prompt window. In either case,
1
searchSlots:
for the
line that says Node Type.
1.3.4
What's in a Name?
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
The
namesgraphical
NetBIOSconfiguration
uses are quite
different
from
DNS hostnames
bebook
familiar
First,
the SWAT
tool.
Updated
forthe
Windows
2000, ME,you
andmight
XP, the
alsowith.
explores
NetBIOS
names
exist
in
a
flat
namespace.
In
other
words,
there
are
no
hierarchical
levels,
such
as
in of
Samba's new role as a primary domain controller and domain member server, its support for the use
oreilly.com
(two
levels)
or
ftp.samba.org
(three
levels).
NetBIOS
names
consist
of
a
single
unique
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
string
navaho
or from
hopi Unix
withinclients.
each workgroup or domain. Second, NetBIOS names are allowed to
sharedsuch
files as
and
printers
be only 15 characters and can consist only of standard alphanumeric characters (a-z, A-Z, 0-9) and the
following:
! @ # $ % ^ & ( ) - ' { } . ~
Although you are allowed to use a period (.) in a NetBIOS name, we recommend against it because those
names are not guaranteed to work in future versions of NBT.
It's not a coincidence that all valid DNS names are also valid NetBIOS names. In fact, the unqualified
DNS name for a Samba server is often reused as its NetBIOS name. For example, if you had a system
with a hostname of mixtec.ora.com , its NetBIOS name would likely be MIXTEC (followed by 9 spaces).
The 1-byte resource type indicates a unique service that the named computer provides. In this book, you
Table of Contents
will often see the resource type shown in angled brackets (<>) after the NetBIOS name, such as:
Index
MIXTEC<00>
Reviews
Reader Reviews
Errata names are registered for a particular NBT computer using the Windows command-line
nbtstat
Using
Samba,
utility.
2nd
Because
Edition these services are unique (i.e., there cannot be more than one registered), you
will
see
them
listed
as type UNIQUE in the output. For example, the following partial output describes the
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
toltec server:
Publisher: O'Reilly
C:\>nbtstat
-a toltec
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
NetBIOS
Slots:
1
Name
Status
--------------------------------------------Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
TOLTEC
<00> UNIQUE
Registered
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
TOLTEC
<03> UNIQUE
Registered
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
TOLTEC
<20> UNIQUE
Registered
...
This says the server has registered the NetBIOS name toltec as a machine (computer) name, as a
recipient of messages from the Windows Messenger service, and as a file server. Some possible
attributes a name can have are listed in Table 1-2.
Named resource
00
Messenger Service
03
06
1B
Table of Contents
name
Master Browser
Index
1D
NetDDE Service
Reviews
Reader Reviews
1F
printer server)
Fileserver (including
Errata
20
21
BE
Publisher:
O'Reilly Utility
Network
Monitor
BF
SMB also uses the concept of groups, with which computers can register themselves. Earlier we
mentioned that the computers in our example belonged to a workgroup, which is a partition of computers
on the same network. For example, a business might very easily have an ACCOUNTING and a SALES
workgroup, each with different servers and printers. In the Windows world, a workgroup and an SMB
Using
Second
Edition is a comprehensive guide to Samba administration. This new edition covers
group Samba,
are the same
thing.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical
configuration
tool.
Updated
for Windows
2000,
and XP,
theMETRAN
book also
explores
Continuing
our nbtstat
example, the
toltec
Samba
server is also
a ME,
member
of the
workgroup
Samba's
newattribute
role as ahex
primary
domain
controller in
and
domain for
member
server,
its support
for attribute
the use of
(the
GROUP
00) and
will participate
elections
the browse
master
(GROUP
Windows
authentication
and output:
filesystem security on the host Unix system, and accessing
1E).
HereNT/2000/XP
is the remainder
of the nbtstat
shared files and printers from Unix clients.
NetBIOS Remote Machine Name Table
Name
Type
Status
--------------------------------------------METRAN
<00>
GROUP
Registered
METRAN
<1E>
GROUP
Registered
..__MSBROWSE__.<01>
GROUP
Registered
The possible group attributes a computer can have are illustrated in Table 1-3. More information is
available in Windows NT in a Nutshell by Eric Pearce, also published by O'Reilly.
Named resource
00
Logon server
1C
1D
1E
name
(administrative)
Internet Group
Table
of Contents
20
<01><02>_ _MSBROWSE_
Index
_<02>
Reviews
01
Reader Reviews
The final entry,
_ _ MSBROWSE _ _, is used to announce a group to other master browsers. The
Errata
nonprinting characters
in the name show up as dots in an nbtstat printout. Don't worry if you don't
Using Samba, 2nd Edition
understand all of the resource or group types. Some of them you will not need with Samba, and others
By
David
Robert
Eckstein
, Jay Tsthe rest of the chapter. The important thing to remember here is
you
willCollier-Brown
pick up as ,you
move
through
the logistics of the naming mechanism.
Publisher: O'Reilly
Pub Date: February 2003
1.3.4.3ISBN:
Scope
ID
0-596-00256-4
Pages: 556
In the Slots:
dark 1ages of SMB networking before NetBIOS groups were introduced, you could use a very
primitive method to isolate groups of computers from the rest of the network. Each SMB packet contains
a field called the scope ID, with the idea being that systems on the network could be configured to accept
only packets with a scope ID matching that of their configuration. This feature was hardly ever used and
unfortunately lingers in modern implementations. Some of the utilities included in the Samba distribution
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
allow the scope ID to be set. Setting the scope ID in a network is likely to cause problems, and we are
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
mentioning scope ID only so that you will not be confused by it when you later encounter it in various
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
places.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
At this point, let's digress to discuss the responsibility of NBT: to provide connection services between
two NetBIOS computers. NBT offers two services: the session service and the datagram service.
Understanding how these two services work is not essential to using Samba, but it does give you an idea
of how NBT works and how to troubleshoot Samba when it doesn't work.
The datagram service has no stable connection between computers. Packets of data are simply sent or
broadcast from one computer to another, without regard to the order in which they arrive at the
destination, or even if they arrive at all. The use of datagrams requires less processing overhead than
sessions, although the reliability of the connection can suffer. Datagrams, therefore, are used for quickly
sending nonvital blocks of data to one or more computers. The datagram service communicates using the
simple primitives shown in Table 1-4.
Description
Send Datagram
Receive Datagram
Receive Broadcast
Datagram
The session service is more complex. Sessions are a communication method that, in theory, offers the
ability to detect problematic or inoperable connections between two NetBIOS applications. It helps to
think of an NBT session as being similar to a telephone call, an analogy that obviously influenced the
design of the CIFS standard.
Once the connection is made, it remains open throughout the duration of the conversation, each side
knows who the caller and the called computer are, and each can communicate with the simple primitives
shown in Table 1-5.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Primitive
Description
Call
Publisher: O'Reilly Wait for a call from a known caller or any caller.
Listen
Pub Date: February 2003
Hang-up
Exit a call.
SendPages: 556
ISBN: 0-596-00256-4
Slots: 1
Receive
Session Status
Using Samba,
Second
Edition
a comprehensive
to network.
Samba administration.
Thisused
new edition
covers
Sessions
are the
backbone
of is
resource
sharing on guide
an NBT
They are typically
for
all versions of
Samba
from 2.0 to
2.2,
including
selected
features
from an
alphaonversion
of 3.0,
well as
establishing
stable
connections
from
client
computers
to disk
or printer
shares
a server.
The as
client
the SWAT
configuration
tool.
Updated for
Windows
and XP,
the book
also
explores
"calls"
the graphical
server and
starts trading
information
such
as which2000,
files ME,
it wishes
to open,
which
data
it wishes
Samba's
new etc.
role These
as a primary
domain
and domain
server,
support
the use
to
exchange,
calls can
last a controller
long timehours,
evenmember
daysand
all ofits
this
occursfor
within
the of
WindowsofNT/2000/XP
authentication
and
security
onsoftware
the host(TCP)
Unix system,
and accessing
context
a single connection.
If there
is filesystem
an error, the
session
will retransmit
until the
shared
files and properly,
printers from
Unix
data
is received
unlike
theclients.
"punt-and-pray" approach of the datagram service (UDP).
In truth, while sessions are supposed to handle problematic communications, they sometimes don't. If
the connection is interrupted, session information that is open between the two computers might become
invalid. If that happens, the only way to regain the session information is for the same two computers to
call each other again and start over.
If you want more information on each service, we recommend you look at RFC 1001. However, there are
two important things to remember here:
Sessions always occur between two NetBIOS computers. If a session service is interrupted, the
client is supposed to store sufficient state information for it to reestablish the connection. However,
in practice, this often does not happen.
Datagrams can be broadcast to multiple computers, but they are unreliable. In other words, there is
no way for the source to know that the datagrams it sent have indeed arrived at their destinations.
Table
of Contentson your first reading. However, assuming you are going to be responsible for
long-term maintenance
of a Samba network, it will help if you understand how it actually works. You will
Index
more easily beReviews
able to diagnose and correct any odd problems that pop up.
Reader Reviews
At a high level, the SMB protocol suite is relatively simple. It includes commands for all the file and print
Errata
operations that you might perform on a local disk or printer, such as:
Using Samba, 2nd Edition
ISBN: 0-596-00256-4
Reading
and writing files
Pages: 556
Searching
for files
Slots: 1
Queueing and dequeueing files in a print spool
Each operation can be encoded into an SMB message and transmitted to and from a server. The original
Using
Second
Edition
is a comprehensive
guide to are
Samba
administration.
new edition
name Samba,
"SMB" comes
from
the way
in which the commands
formatted:
they areThis
versions
of the covers
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as to
well as
standard DOS system-call data structures, or Server Message Blocks, redesigned for transmitting
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
another computer across a network.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
RichardSharpe of the Samba team defines SMB as a request-response protocol. [4] In effect, this means
that a client sends an SMB request to a server and the server sends an SMB response back to the client.
In only one rare circumstance does a server send a message that is not in response to a client.
[4]
AnSMB message is not as complex as you might think. Let's take a closer look at the internal structure
of such a message. It can be broken down into two parts: the header, which is a fixed size, and the
command string, whose size can vary dramatically based on the contents of the message.
Field
Size (bytes)
Description
0xFF 'SMB'
Protocol identifier
COM
RCLS
Error class
REH
Reserved
ERR
2 of Contents
Table
Error code
REB
Index
1
Reserved
Reviews
RES
14 Reviews
Reader
Reserved
TID
Errata
2
PID
Caller process ID
UID
User identifier
Publisher: O'Reilly
MID
ISBN: 0-596-00256-4
Immediately after the header is a variable number of bytes that constitute an SMB command or reply.
Each command, such as Open File (COM field identifier: SMBopen) or Get Print Queue (SMBsplretq ), has
its own set of parameters and data. Like the SMB header fields, not all of the command fields need to be
filled,
on the
specific
command.
For example,
Get Server
AttributesThis
(SMBdskattr)
Using depending
Samba, Second
Edition
is a
comprehensive
guide tothe
Samba
administration.
new edition covers
command
the WCT
and2.0
BCC
to zero. The
fieldsfeatures
of the command
segment
are shown
all versionssets
of Samba
from
to fields
2.2, including
selected
from an alpha
version
of 3.0, in
asTable
well as
1-7.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Size (bytes)
Description
WCT
Word count
VWV
Variable
BCC
DATA
Variable
Don't worry if you don't understand each field; they are not necessary for using Samba at an
administrator level. However, they do come in handy when debugging system messages. We will show
you some of the more common SMB messages that clients and servers send using a modified version of
tcpdump later in this section. (If you prefer an SMB sniffer with a graphical interface, try Ethereal, which
uses the GTK libraries; see http://www.ethereal.com for more information on this tool.)
For more information on each command in the SMB protocol, see the CIFS
Technical Reference at http://www.snia.org/tech_activities/CIFS.
Table 1-8 outlines the major versions of the SMB protocol. Within each "dialect" of SMB are many subversions that include commands supporting particular releases of major operating systems. The ID string
in column 2 is used by clients and servers to determine in which level of the protocol they will speak to
each other.
Table of Contents
Index
Protocol
name
Reviews
Core
Reader Reviews
Errata
ID string
PC NETWORK PROGRAM 1.0
CoreSamba,
Plus 2nd Edition
Using
LANMAN1.0
LAN
Manager
2.0
Publisher:
O'Reilly
LM1.2X002
Used by
LANMAN2.1
NT LAN
Manager
1.0
Pages:
556
NT LM 0.12
Windows NT 4.0
Samba's NT LM 0.12
Samba
Samba
CIFS 1.0
Windows 2000/XP
ISBN: 0-596-00256-4
Slots: 1
Using Samba,
Second
a comprehensive
guide
to Samba
administration.
This new edition covers
Samba
implements
theEdition
NT LMis0.12
specification for
NT LAN
Manager
1.0. It is backward-compatible
with
versions
Samba
from The
2.0 to
2.2,
including selected
features
an alpha
3.0,
as well as
all the
otherof
SMB
variants.
CIFS
specification
is, in reality,
LANfrom
Manager
0.12version
with a of
few
specific
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
additions.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
As mentioned earlier, SMB is a client/server protocol. In the purest sense, this means that a client sends
a request to a server, which acts on the request and returns a reply. However, the client/server roles can
often be reversed, sometimes within the context of a single SMB session. For example, consider the two
Windows 95/98/Me computers in Figure 1-11. The computer named maya shares a printer to the network,
and the computer named toltec shares a disk directory. maya is in the client role when accessing
toltec's network drive and in the server role when printing a job for toltec.
common to find Windows acting as a server, client, both, or neither at any given time in a production
network. Although Samba has been developed primarily to function as a server, there are also ways that
it and associated software can act as an SMB client. As with Windows, it is even possible to set up a Unix
system to act as an SMB client and not as a server. See Chapter 5 for more details on this topic.
of Contents
Index
Reviews
2. Negotiate
Errata
the protocol variant.
Using Samba, 2nd Edition
Set
session parameters,
and
make
By3.
David
Collier-Brown
, Robert Eckstein
, Jay
Ts
We will examine each step through the eyes of a useful tool that we mentioned earlier: the modified
Publisher: O'Reilly
tcpdump that is available from the Samba web site.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
NameType=0x20 (Server)
Source=MAYA
NameType=0x00 (Workstation)
Table of Contents
Flags=0x0
Index
Reviews
Length=154
Reader Reviews
Errata
0x72
Error ISBN:
class
= 0x0
0-596-00256-4
Pages: 556
Error Slots:
code1
Flags1
0x0
Flags2
= 0x0
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of Samba
Tree
ID
= 0 from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
a primary domain controller and domain member server, its support for the use of
Proc ID new role
= as5315
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and =
printers
from Unix clients.
UID
0
MID
257
Word Count
0x72
Error class
0x0
Error code
0x80
Flags1
Table of Contents
Flags2
Index
= 0x1
Reviews
Tree
ID
Reader
= 0Reviews
Errata
Proc
ID
= 5315
Using Samba,
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
UID
MIDPublisher: O'Reilly=
257
NT1 Protocol
Slots: 1
DialectIndex=5
[...]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
In this example, the server responds with the value 5, which indicates that the NTLM0.12 dialect will be
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
used for the remainder of the session.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
The next step is to transmit session and login parameters for the session, which you do using the
SMBSesssetupX command. The parameters include the following:
The account name and password (if there is one)
The workgroup name
The maximum size of data that can be transferred
The number of pending requests that can be in the queue at a time
The resulting output from tcpdumpis:
>>> NBT Packet
NBT Session Packet
Flags=0x0
Length=150
0x73
Error class
0x0
Error code
Flags1
0x10
Flags2
0x0
Tree ID
Proc
ID
= of5315
Table
Contents
Index
UID
= 1
Reviews
Reader Reviews
Errata
MID
257
Word Count
13
Com2=0x75
Publisher: O'Reilly
Res1=0x0
Pub Date: February
2003
ISBN: 0-596-00256-4
Off2=120
Pages: 556
Slots: 1
MaxBuffer=2920
MaxMpx=50
Using
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
VcNumber=0
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
SessionKey=0x1380
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
CaseInsensitivePasswordLength=24
shared files and printers from Unix clients.
CaseSensitivePasswordLength=0
Res=0x0
Capabilities=0x1
Pass1&Pass2&Account&Domain&OS&LanMan=
JAY METRAN Windows 4.0 Windows 4.0
In this example, the SMBsesssetupX Session Setup command allows for an additional SMB command to
be piggybacked onto it (indicated by the letter X at the end of the command name). The hexadecimal
code of the second command is given in the Com2 field. In this case the command is 0x75, which is the
SMBtconX(Tree Connect and X) command. The SMBtconX message looks for the name of the resource in
thesmb_buf buffer. In this example, smb_buf contains the string \\TOLTEC\SPIRIT, which is the full
pathname to a shared directory on toltec. Using the "and X" commands like this speeds up each
transaction because the server doesn't have to wait on the client to make a second request.
Note that the TID is still zero. Finally, the server returns a TID to the client, indicating that the user has
Table
of Contents
been authorized
access
and that the resource is ready to be used:
Index
>>>
NBT Packet
Reviews
Reader Reviews
NBT
Session Errata
Packet
Flags=0x0
Length=85
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
SMB PACKET:
Pages: 556SMBsesssetupX (REPLY)
Slots: 1
SMB Command
0x73
Error class
0x0
Using
Error Samba,
code Second
= 0 Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Flags1
= 0x80
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
authentication and filesystem security on the host Unix system, and accessing
Flags2 NT/2000/XP
= 0x1
shared files and printers from Unix clients.
Tree ID
Proc ID
5315
UID
100
MID
257
Word Count
Com2=0x75
Off2=68
Action=0x1
[000] Unix Samba 2.2.6
[010] METRAN
smbbuf[]=
ServiceType=A:
TheServiceType field is set to "A" to indicate that this is a file service. Available service types are:
"A" for a disk or file
"LPT1" for
a spooled
output
Table
of Contents
Index
Reviews
"IPC" forReader
a named
pipe
Errata
Using
Samba,
2nd has
Edition
Now that
a TID
been
assigned, the client can use it as a handle to perform any operation that it
would
on a local
disk Eckstein
drive. It
can
By
Daviduse
Collier-Brown
, Robert
, Jay
Ts open files, read and write to them, delete them, create new files,
search for filenames, and so on.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
1.5.1 Windows
Workgroups
Errata
Windows Workgroups are very similar to the SMB groups already described. You need to know just a few
By
David Collier-Brown
additional
things. ,Robert Eckstein,Jay Ts
Publisher: O'Reilly
1.5.1.1
Browsing
Pub Date:
February 2003
ISBN: 0-596-00256-4
Browsing
is 556
the process of finding the other computers and shared resources in the Windows network.
Pages:
Note that
there
is no connection with a World Wide Web browser, apart from the general idea of
Slots: 1
"discovering what's there." On the other hand, browsing the Windows network is like the Web in that
what's out there can change without warning.
Before browsing existed, users had to know the name of the computer they wanted to connect to on the
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
network and then manually enter a UNC such as the following into an application or file manager to
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
access resources:
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
\\toltec\spirit\
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files
and printers
from Unix clients.
Browsing
is much
more convenient,
making it possible to examine the contents of a network by using the
point-and-click GUI interface of the Network Neighborhood (or My Network Places[5]) on a Windows
client.
[5]
This was originally called Network Neighborhood in Windows 95/98/NT, but Microsoft has changed the name to My
Network Places in the more recent Windows Me/2000/XP. We will continue to call it Network Neighborhood, and if
you're using a new version of Windows, be aware that My Network Places can act a little differently in some ways.
The Windows Network Neighborhood can behave oddly: until you select a particular
computer to browse, the Network Neighborhood window might contain data that is
not up-to-date. That means the Network Neighborhood window can be showing
computers that have crashed or can be missing computers that haven't been
noticed yet. Put succinctly, once you've selected a server and connected to it, you
can be a lot more confident that the shares and printers really exist on the
network.
Table of Contents
Index
Unlike the roles you've seen earlier, almost any Windows system (including Windows for Workgroups and
Reviews
Windows 95/98/Me or NT/2000/XP) can act as a local master browser. The local master browser can have
Reader Reviews
one or more backup browsers on the local subnet that will take over in the event that the local master
Errata
browser fails or
becomes inaccessible. To ensure fluid operation, the local backup browsers will frequently
Using Samba, 2nd Edition
synchronize their browse list with the local master browser.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Here is how to calculate the minimum number of backup browsers that will be allocated on a workgroup:
Publisher: O'Reilly
Pub
February
2003
IfDate:
up to
32 Windows
If the number of Windows NT/2000/XP workstations falls between 33 and 64, or the number of
Windows 95/98/Me workstations falls between 17 and 32, the local master browser allocates two
backup browsers.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
For each group of 32 NT/2000/XP workstations or 16 Windows 95/98/Me computers beyond this,
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the local master browser allocates another backup browser.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role no
as a
primary
domain
member
server,
support by
for the
thelocal
use of
There is currently
upper
limitdomain
on the controller
number ofand
backup
browsers
that
can beitsallocated
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
master browser.
shared files and printers from Unix clients.
These values determine which operating system has seniority and will fulfill the role of the local master
browser. (Chapter 7 describes the election process in more detail.) The architecture developed to achieve
this is not elegant and has built-in security problems. While a browsing domain can be integrated with
domain security, the election algorithm does not take into consideration which computers become
browsers. Thus it is possible for any computer running a browser service to register itself as participating
in the browsing election and (after winning) being able to change the browse list. Nevertheless, browsing
is a key feature of Windows networking, and backward-compatibility requirements will ensure that it is in
use for years to come.
Table of Contents
Index
1.5.1.3 Windows
95/98/Me authentication
Reviews
Reader Reviews
Errata
Three types of passwords arise when Windows 95/98/Me is operating in a Windows workgroup:
Using Samba, 2nd Edition
A Collier-Brown
Windows password
ByDavid
, Robert Eckstein, Jay Ts
A Windows Networking password
Publisher: O'Reilly
Pub
Februaryfor
2003
ADate:
password
each
ISBN: 0-596-00256-4
The Windows
Pages: 556password functions in a manner that might be a source of confusion for Unix system
administrators.
It is not there to prevent unauthorized users from using the computer. (If you don't
Slots: 1
believe that, try clicking the Cancel button on the password dialog box and see what happens!) Instead,
the Windows password is used to gain access to a file that contains the Windows Networking and network
resource passwords. There is one such file per registered user of the system, and they can be found in
theC:\Windows directory with a name composed of the user's account name, followed by a .pwl
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
extension. For example, if the user's account name is "sarah," the file will be C:\Windows\sarah.pwl. This
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
file is encrypted using the Windows password as the encryption key.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
a security
you might want to check for junk .pwl files on Windows
shared files andAs
printers
frommeasure,
Unix clients.
95/98/Me clients, which might have been created by mistakes users made while
attempting to log on. A .pwl file is easily cracked and can contain valid passwords
for Samba accounts and network shares.
The first time the network is accessed, Windows attempts to use the Windows password as the Windows
Networking password. If this is successful, the user will not be prompted for two separate passwords,
and subsequent logins to the Windows system will automatically result in logging on to the Windows
network as well, making things much simpler for the user.
Shared network resources in the workgroup can also have passwords assigned to them to limit their
accessibility. The first time a user attempts to access the resource, she is asked for its password, and a
checkbox in the password dialog box gives the user the option to add the password to her password list.
This is the default; if it is accepted, Windows will store the password in the user's .pwl file, and all further
authentication to the resource will be handled automatically by Windows.
Samba's approach to workgroup authentication is a little different, which is a result of blending the
Windows workgroup model with that of the Unix host upon which Samba runs. This will be discussed
further in Chapter 9.
To support the needs of larger networks, such as those found in departmental computing environments,
Microsoft introduced domains with Windows NT 3.51. A Windows NT domain is essentially a workgroup of
SMB computers that has one addition: a server acting as a domain controller (see Figure 1-12).
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date:
Februarycontrollers
2003
1.5.2.1
Domain
ISBN: 0-596-00256-4
Pages:
556
domain
controller
A
in a Windows NT domain functions much like a Network Information Service (NIS)
1
server Slots:
in a Unix
network, maintaining a domain-wide database of user and group information, as well as
performing related services. The responsibilities of a domain controller are mainly centered around
security, including authentication, the process of granting or denying a user access to the resources of
the domain. This is typically done through the use of a username and password. The service that
maintains
the database
on theisdomain
controllers guide
is called
the Security
Account Manager
(SAM).
Using Samba,
Second Edition
a comprehensive
to Samba
administration.
This new
edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
The
NT security
model revolves
around for
security
identifiers
(SIDs)
control
the Windows
SWAT graphical
configuration
tool. Updated
Windows
2000, ME,
andand
XP,access
the book
also lists
explores
(ACLs).
Security
identifiers
are
used
to
represent
objects
in
the
domain,
which
include
(but
are
not
Samba's new role as a primary domain controller and domain member server, its support for
the
use of
limited
to)
users,
groups,
computers,
and
processes.
SIDs
are
commonly
written
in
ASCII
form
as
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
hyphen-separated
fields, from
like this:
shared files and printers
Unix clients.
S-1-5-21-1638239387-7675610646-9254035128-545
The part of the SID starting with the "S" and leading up to the rightmost hyphen identifies a domain. The
number after the rightmost hyphen is called a relative identifier (RID) and is a unique number within the
domain that identifies the user, group, computer, or other object. The RID is the analog of a user ID
(UID) or group ID (GID) on a Unix system or within an NIS domain.
ACLs supply the same function as "rwx" file permissions that are common in Unix systems. However,
ACLs are more versatile. Unix file permissions only set permissions for the owner and group to which the
file belongs, and "other," meaning everyone else. Windows NT/2000/XP ACLs allow permissions to be set
individually for any number of arbitrary users and/or groups. ACLs are made up of one or more access
control entries (ACEs), each of which contains an SID and the access rights associated with it.
ACL support has been added as a standard feature for some Unix variants and is available as an add-on
for others. Samba supports mappings between Windows and Unix ACLs, and this will be covered in
Chapter 8.
servers. The systems that are considered members of the domain are a more exclusive class, composed
of the PDC and BDCs, as well as domain member servers, which are systems that have joined a domain
as members, and are known to the domain controllers by having a computer account in the SAM
database.
1.5.2.3 Authentication
When
a user logs
to a Windows domain by typing in a username and password, a secure challenge
Tableon
of Contents
and
response
protocol
is invoked between the client computer and a domain controller to verify that the
Index
username
and
password
are valid. Then the domain controller sends a SID back to the client, which uses
Reviews
it to create a Security Access Token (SAT) that is valid only for that system, to be used for further
Reader Reviews
authentication. This access token has information about the user coded into it, including the username,
Errata
the group, and the rights the user has within the domain. At this point, the user is logged on to the
Using Samba, 2nd Edition
domain.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Subsequently, when the client attempts to access a shared resource within the domain, the client system
enters
into a
secure challenge and response exchange with the server of the resource. The server then
Publisher:
O'Reilly
enters
into
another
secure challenge and response conversation with a domain controller to check that
Pub Date: February 2003
the client is valid. (What actually happens is that the server uses information it gets from the client to
ISBN: 0-596-00256-4
pretend to be the client and authenticate itself with the domain controller. If the domain controller
Pages: 556
validates the credentials, it sends an SID back to the server, which uses the SID to create its own SAT for
Slots: 1
the client
to enable access to its local resources on the client's behalf.) At this point, the client is
authenticated for resources on the server and is allowed to access them. The server then uses the SID in
the access token to determine what permissions the client has to use and modify the requested resource
by comparing them to entries in the ACL of the resource.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Although
this
authentication
might seem
overly
complicated,
it allows
clients to
all versions
of method
Samba of
from
2.0 to 2.2, including
selected
features
from an
alpha version
of authenticate
3.0, as well as
without
having
plain-text
passwords
travel
through
the network,
and
it is
much
difficult
crack
the SWAT
graphical
configuration
tool.
Updated
for Windows
2000,
ME,
and
XP, more
the book
also to
explores
than
the relatively
weak
workgroup
security
we described
earlier.
Samba's
new role as
a primary
domain
controller
and domain
member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Server. It is compatible with DNS that is standard on virtually every Unix system, and a Unix server
(such as the Samba host) can also be used for DNS.
of Contents
followed
is
called
pass-through
authentication,in which the user's credentials are passed from the client
Index
system
in
the
first
domain
to
the
server in the second domain, which consults a domain controller in the
Reviews
first (trusted) domain to check that the user is valid before granting access to the resource.
Reader Reviews
Errata
Note that in many
aspects, the behaviors of a Windows workgroup and a Windows NT domain overlap.
Using Samba, 2nd Edition
For example, the master and backup browsers in a domain are always the PDC and BDC, respectively.
By
David
Collier-Brown
, Robert Eckstein
, Jay
Ts
Let's
update
our Windows
domain
diagram
to include both a local master and local backup browser. The
result is shown in Figure 1-13.
Publisher: O'Reilly
Pub Date: February 2003
Figure
1-13. A Windows domain with a local master and local backup
ISBN: 0-596-00256-4
browser
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
The similarity between workgroups and NT domains is not accidental because the concept of Windows
domains did not evolve until Windows NT 3.5 was introduced, and Windows domains were forced to
remain backward-compatible with the workgroups present in Windows for Workgroups.
Samba can function as a primary domain controller for Windows 95/98/Me and Windows NT/2000/XP
clients with the limitation that it can act as a PDC only, and not as a BDC.
Samba can also function as a domain member server, meaning that it has a computer account in the
PDC's account database and is therefore recognized as being part of the domain. A domain member
server does not authenticate users logging on to the domain, but still handles security functions (such as
file permissions) for domain users accessing its resources.
operate in native mode, Windows 2000 servers support only Active Directory. Even so, Samba 2.2 can
operate as a server in a domain hosted by a native-mode Windows 2000 server, using the Windows 2000
server'sPDC emulation mode. However, it is not possible for Samba 2.2 or 3.0 to operate as a domain
controller in a Windows 2000 Active Directory domain.
If you want to know more about Active Directory, we encourage you to obtain a copy of the O'Reilly
book,Windows 2000 Active Directory.
of Contents
1.5.4
Can aTable
Windows
Workgroup Span Multiple Subnets?
Index
Reviews
Yes,
but mostReader
peopleReviews
who have done it have had their share of headaches. Spanning multiple subnets
was not part of the initial design of Windows NT 3.5 or Windows for Workgroups. As a result, a Windows
Errata
domain that spans two or more subnets is, in reality, the "gluing" together of two or more workgroups
Using Samba, 2nd Edition
that share an identical name. The good news is that you can still use a PDC to control authentication
By
David each
Collier-Brown
, Robert
Eckstein
, Jay
across
subnet.
The bad
news
isTsthat things are not as simple with browsing.
As mentioned
previously, each subnet must have its own local master browser. When a Windows domain
Publisher: O'Reilly
spans
multiple
subnets,
Pub Date: February
2003 a system administrator will have to assign one of the computers as the domain
masterISBN:
browser.
The
domain master browser will keep a browse list for the entire Windows domain. This
0-596-00256-4
browse list is created by periodically synchronizing the browse lists of each local master browser with the
Pages: 556
browse list of the domain master browser. After the synchronization, the local master browser and the
1
domainSlots:
master
browser should contain identical entries. See Figure 1-14 for an illustration.
Sound good? Well, it's not quite nirvana for the following reasons:
If it exists, a PDC always plays the role of the domain master browser. By Microsoft design, the two
always share the NetBIOS resource type <1B> and (unfortunately) cannot be separated.
Windows 95/98/Me computers cannot become or even contact a domain master browser. This
means that it is necessary to have at least one Windows NT/2000/XP system (or Samba server) on
each subnet of a multisubnet workgroup.
Each subnet's local master browser continues to maintain the browse list for its subnet, for which it
becomes authoritative. So if a computer wants to see a list of servers within its own subnet, the local
master browser of that subnet will be queried. If a computer wants to see a list of servers outside the
subnet, it can still go only as far as the local master browser. This works because at appointed intervals,
the authoritative browse list of a subnet's local master browser is synchronized with the domain master
browser, which is synchronized with the local master browser of the other subnets in the domain. This is
called browse list propagation .
Samba can act as a domain master browser in a Windows NT domain, or it can act as a local master
of Contents
browser for a Table
subnet,
synchronizing its browse list with the domain master browser.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
Index
Reviews
Reviews
1.6.1 PDC Reader
Support
for Windows 2000/XP Clients
Errata
Samba previously could act as a PDC to authenticate Windows 95/98/Me and Windows NT 4 systems.
By
David
Collier-Brown
, Robert
, Jay Ts
This
functionality
has
beenEckstein
extended
in Release 2.2 to include Windows 2000 and Windows XP. Thus, it is
possible to have a Samba server supporting domain logons for a network of Windows clients, including
the Publisher:
most recent
O'Reillyreleases from Microsoft. This can result in a very stable, high-performance, and more
secure
network,
and gives you the added benefit of not having to purchase per-seat Windows CALs from
Pub Date: February 2003
Microsoft.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
1.6.4 ACLs
Samba now supports ACLs on its Unix host for Unix variants that support them. The list includes Solaris
2.6, 7, and 8, Irix, AIX, Linux (with either the ACL patch for the ext2/ext3 filesystem from
http://acl.bestbits.at or when using the XFS filesystem), and FreeBSD (Version 5.0 and later). When
using ACL support, Samba translates between Unix ACLs and Windows NT/2000/XP ACLs, making the
Samba host look and act more like a Windows NT/2000/XP server from the point of view of Windows
clients.
to authenticate on a Unix system. The result is a unified logon environment, in which a user account can
be kept on either the Unix system or a Windows NT/2000 domain controller. This greatly facilitates
account management because administrators no longer need to keep the two systems synchronized, and
it is possible for users whose accounts are held in a Windows domain to authenticate when accessing
Samba shares.
Table of Contents
Samba servers
to support Unix filesystem attributes, such as links and permissions, when sharing files
Reviews
with other Unix
systems.
This allows Samba to be used as an alternative to network file sharing (NFS) for
Reader
Reviews
Unix-to-Unix
file
sharing. An advantage of using Samba is that it authenticates individual users, whereas
Errata
NFS
only clients (based on their IP addresses, which is a poor security model). This gives
Usingauthenticates
Samba, 2nd Edition
Samba an edge in the area of security, along with its much greater configurability. See Chapter 5 for
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
information on how to operate Unix systems as Samba clients.
Publisher: O'Reilly
Pub Date: February 2003
1.6.8
And More...
ISBN: 0-596-00256-4
Pages: 556
As usual, the code has numerous improvements that do not show up at the administrative level in an
Slots: 1
immediate
or obvious way. Samba now functions better on systems that employ PAM (Pluggable
Authentication Modules), and there is new support for profiling. Samba's support for oplocks has been
strengthened, offering better integration with NFS server-terminated leases (currently on Irix and Linux
only) and in the local filesystem with SMB locks mapped to POSIX locks (which is dependent on each Unix
Using Samba,
Second Edition
is a comprehensive
guide to
Samba
administration.
This
edition covers
variant's
implementation
of POSIX
locks). And of course
there
have
been the usual
bugnew
fixes.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
In
3 releases, the Samba team plans to develop support for WINS replication, allowing
later Version
Index
Samba
to
act
as
a secondary WINS server or as a primary WINS server with Windows or Samba
Reviews
secondary
WINS
servers. Also planned are support for acting as a Windows NT BDC and support for
Reader Reviews
Windows NT domain trust relationships.
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
them. As of Version
Index 3.0, Samba cannot act as a backup in most roles and does not yet fully support
Active Directory.
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
File server
ISBN: 0-596-00256-4
Pages: 556
Role
Can perform?
Yes
Printer server
Yes
Yes
Yes
Slots: 1
Using
Backup
Samba,
domain
Second
controller
Edition is a comprehensive guide to Samba administration.No
This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Active
Directory
domain
controller
No book also explores
the
SWAT
graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the
Samba's
role as authentication
a primary domain controller and domain member server, itsYes
support for the use of
Windowsnew
95/98/Me
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Windows
authentication
Yes
shared
filesNT/2000/XP
and printers
from Unix clients.
Local master browser
Yes
Yes
Yes
Yes
No
Table of Contents
The
majority of
the programs that come with Samba center on its two daemons. Let's take a refined look
Index
at
the
responsibilities
Reader Reviews
Errata
nmbd
Using Samba,
2nd Edition
Thenmbd
daemon
is a simple name server that supplies WINS functionality. This daemon listens
the appropriate IP addresses when called upon. It also
provides browse lists for the Network Neighborhood and participates in browsing elections.
ByDavidfor
Collier-Brown
name-server
, Robert
requests
Ecksteinand
, Jay Ts
provides
smbd
Publisher: O'Reilly
Pub Date: February 2003
Thesmbd daemon manages the shared resources between the Samba server and its clients. It
ISBN: 0-596-00256-4
provides
file, print, and browse services to SMB clients across one or more networks and handles
Pages:
556
all notifications
between the Samba server and the network clients. In addition, it is responsible for
Slots: authentication,
1
user
resource locking, and data sharing through the SMB protocol.
smbclient
Anftp-like Unix client that can be used to connect to SMB shares and operate on them. The
smbclient command is discussed in detail in Chapter 5.
smbcontrol
A simple administrative utility that sends messages to nmbd or smbd.
smbgroupedit
A command
can be used to define mappings between Windows NT groups and Unix groups. It
Table that
of Contents
is new in
Samba 3.0.
Index
smbmnt
Reviews
Reader Reviews
ByDavidACollier-Brown
, Robert
Eckstein
Ts
program that
mounts
an,Jay
smbfs
ASlots:
tool1 that functions like a command shell to allow access to a remote SMB filesystem and allow
Unix utilities to operate on it. This command is covered in Chapter 5.
smbspool
print-spooling
program
to send files guide
to remote
printers
that are shared
onnew
the edition
SMB network.
Using A
Samba,
Second Edition
is used
a comprehensive
to Samba
administration.
This
covers
smbstatus
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
A program that reports the current network connections to the shares on a Samba server.
Samba's new role as a primary domain controller and domain member server, its support for the use of
smbtar
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
A program similar to the Unix tar command, for backing up data in SMB shares.
smbumount
A program that works along with smbmount to unmount smbfs filesystems.
testparm
A simple program for checking the Samba configuration file.
testprns
A program that tests whether printers on the Samba host are recognized by the smbd daemon.
wbinfo
A utility used to query the winbindd daemon.
Each major release of Samba goes through an exposure test before it's announced. In addition, it is
quickly updated afterward if problems or unwanted side effects are found. The latest stable distribution as
of this writing is Samba 2.2.6, and this book focuses mainly on the functionality supported in Samba
2.2.6, as opposed to older versions of Samba.
Table of Contents
Most
Linux and
many Unix vendors provide binary packages. These can be more convenient to install and
Index
maintain
than
the
Samba team's source or binary packages, due to the vendor's efforts to supply a
Reviews
package
that
matches
its specific products.
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
on the right foot.
Index
For illustrativeReviews
purposes, we will be installing the 2.2.6 version of the Samba server on a Linux system
Reader
running Version
2.4 Reviews
of the kernel. However, the installation steps are essentially the same for all the
Errata
platforms Samba
supports.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Contents
developments.Index
On the other hand, you can be fairly sure that a bundled version has been installed
Reader Reviews
needs,
so youErrata
might be perfectly happy running a bundled version.
If you choose this option, be aware that your Samba files, including the very important smb.conf, might
By
Collier-Brown
, Robert
, Jay Ts be if you were to install from a binary or source distribution. For
beDavid
in different
places
thanEckstein
they would
example, with the Red Hat, Debian, and Mandrake Linux distributions, smb.conf and some other Sambarelated
Publisher:
filesO'Reilly
are in the /etc/samba directory.
Pub Date: February 2003
If Samba
is already installed on your system, you can check to see what version you have by using the
ISBN: 0-596-00256-4
command:
Pages: 556
$smbd Slots:
-V 1
Version 2.2.6
(If
thisSamba,
doesn'tSecond
work, itEdition
might is
beabecause
smbd is guide
not into
your
shell's
search path. If
younew
have
the locate
Using
comprehensive
Samba
administration.
This
edition
covers
or
your2.0
Unix
you can
use it to
locate the
executable.)
allwhereis
versionscommand
of Sambainfrom
to variant,
2.2, including
selected
features
fromsmbd
an alpha
version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
You
mightnew
alsorole
be as
able
to use a domain
system-specific
tool
query amember
software-package
utility.
On
Samba's
a primary
controller
andtodomain
server, its maintenance
support for the
use of
Red
Hat
Linux,
you
can
use
the
rpm
command
to
query
the
installed
packages
for
Samba:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
$rpm -qa | grep samba
samba-client-2.0.8-1.7.1
samba-2.0.8-1.7.1
samba-common-2.0.8-1.7.1
This shows we have Samba 2.0.8, divided into three Red Hat Package Manager (RPM) packages, bundled
with Red Hat 7.1. If your version of Samba is old, you might at the very least want to check with your
vendor for an update.
Otherwise, if you're sure you are going to install from a binary or source distribution, you can remove the
RPM packages as follows:
#rpm -e samba
#rpm -e samba-client
#rpm -e samba-common
If you are not using Red Hat Linux, consult your system's documentation to find the method that works
for you.
couple of issues in mind when deciding whether to use the binary or compile the source yourself:
The binary packages can lag behind the latest version of the software by one or two (maybe more)
minor releases, especially after a series of small changes and for less popular platforms. Compare
the release notes for the source and binary packages to make sure there aren't any new features
that you need on your platform.
If you use a precompiled binary that is dynamically linked, you will need to ensure that you have the
correct libraries
required by the executables. If your system does not already have the required
Table of Contents
version of
a library, you might have to install a new version. The README file or makefile that
Index
accompanies
the binary distribution should list any special requirements.
Reviews
Reader Reviews
Many systems with shared libraries come with a nifty tool called ldd. This tool will tell you which
Errata
libraries a specific binary requires and which libraries on the system satisfy that requirement. For
Using Samba, 2nd Edition
example, checking the smbd program on our test machine gave us:
ByDavid
Collier-Brown
$ldd
smbd ,Robert Eckstein,Jay Ts
libdl.so.2
Publisher: O'Reilly
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
binaries are available for almost every modern machine. See http://www.gnu.org/ for a list of sites with gcc and
other GNU software.
A typical installation will take about an hour to complete, including downloading the source files and
compiling them, setting up the configuration files, and testing the server.
Here is an overview of the steps:
1. Download the source or binary files.
2. Read the installation documentation.
3.
4.
2.
3. Configure a makefile.
4. Compile the server and utility programs.
5. Install the server files.
6. Create a Samba configuration file.
7. Test the configuration file.
Table of Contents
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
location.
Index
Reviews
The
standard Reader
SambaReviews
web sites have Samba documentation and tutorials,mailing-list archives, and the
latest Samba news, as well as source and binary distributions of Samba. The download sites (sometimes
Errata
called F T P sites) have only the source and binary distributions. Unless you specifically want an older
Using Samba, 2nd Edition
version of the Samba server or are going to install a binary distribution, download the latest source
By
David Collier-Brown
, Robert
Eckstein
, Jaysite.
Ts This distribution is always named:
distribution
from the
closest
mirror
samba-latest.tar.gz
Publisher: O'Reilly
Pub Date: February 2003
Pages: 556
source
distribution
The
has been archived with tar and then compressed with the GNU gzip program. To
1
unpackSlots:
it, move
the file to the directory in which you want the Samba source directory to be located,
thencd to that directory and run the command:
$tar xvfz samba-latest.tar.gz
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Or,
if you doofnot
have from
the GNU
tar2.2,
program
(which
also handles
unzipping):
all versions
Samba
2.0 to
including
selected
featuresthe
from
an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
$gunzip samba-latest.tar.gz
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
$tar xvf samba-latest.tar
shared files and printers from Unix clients.
In that latter case, you might need to install the GNU gunzip program first. While the tar command runs,
it will print out a list of the files it installs.
docs/htmldocs
This is the miscellaneous documentation in HTML format.
docs/textdocs
Here is more documentation, in simple text format.
docs/manpages
You don't need to worry about these yet; during the installation, the files will be installed so that
you canTable
use the
man command to read them. But you can take a look in the directory to see which
of Contents
manpages
are available.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
generated
through
a
GNU
configure script, which is located in the samba-2.2.x /source/ directory. The
Index
configure
script
takes
care
of the machine-specific issues of building Samba.
Reviews
Reader Reviews
Errata
Before running the configure script, it is important that you become the root user
you might get a warning such as:
ByDavid Collier-Brown
Robert
Eckstein
, Jay Ts
on ,the
system.
Otherwise,
configure:
Publisher: O'Reilly
You don't want any test to be disabled when the Samba makefile is being created;
it would leave the potential for errors down the road when compiling or running
Samba on your system.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
When the configure script is run, it prints out messages telling what it is doing, and error messages might
be mixed in. To make sure you see those very important error messages, we suggest you run configure
with its standard output passed through some filter to capture the output and keep it from scrolling out of
Using
Second
Edition
a comprehensive
sight. Samba,
One method
is using
theismore
command: guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
#
./configure
| more
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
and filesystem security on the host Unix system, and accessing
We
will show
you another
in a moment.
shared files and printers from Unix clients.
Although you can run configure as previously with no options, you might want to add support for extra
features by passing options on the command line. For example:
#./configure --with-winbind
will configure the Samba makefile with support for winbind authentication. If you would like a complete
list of options, type the following:
#./configure --help
Each option enables or disables various features. You typically enable a feature by specifying the --withfeature option, which will cause the feature to be compiled and installed. Likewise, if you specify a -without-feature option, the feature will be disabled. A full list of configuration options is provided in
Appendix E, but for now we want to point out three of them, which are features we cover later in this
book:
--with-msdfs
Include support for Microsoft Distributed filesystem (Dfs), which allows dispersed network
resources to be clumped together into one easy-to-navigate directory tree. See Chapter 8.
--with-smbwrapper
Include SMB wrapper support, which allows programs running on the Unix host to access SMB
shared folders as if they were Unix filesystems. We recommend using this option. See Chapter 5.
--with-smbmount
Includesmbmount support, which allows SMB shared folders to be mounted in the Unix filesystem.
At the time of this writing, support for this feature exists only for Linux. This is also covered in
Chapter 5.
Each option is disabled by default, and none of the features is essential to Samba. However, you may
want to include them in your configuration (as we will in our example) at least to be able to try out the
options in later chapters.
In addition, Table 2-1 shows some other parameters that you can give the configure script if you wish to
store parts of the Samba distribution in different places, perhaps to make use of multiple disks or
partitions. Note that the defaults sometimes refer to a prefix specified earlier in the table.
Table of Contents
Index
Reviews
Reader Reviews
Option
Meaning
Errata
Default
--prefix=directory
--eprefix=directory
Publisher: O'Reilly
--bindir=directory
ISBN: 0-596-00256-4
Pages: 556
--sbindir=directory
Slots: 1
-libexecdir=directory
/usr/local/samba
eprefix/bin
eprefix/bin
eprefix/libexec
read-only architecture-independent
data in theThis new edition covers
Using
Samba, Second EditionInstall
is a comprehensive
guide to Samba administration.
--datadir=directory
prefix/share
directory
all versions of Samba from 2.0
to 2.2,specified.
including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
--libdir=directory
Install program libraries in the directory specified.
eprefix/lib
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
-Install
files in the directory specified.
prefix/include
shared
files and printers from
Unix package-include
clients.
includedir=directory
--infodir=directory
prefix/info
--mandir=directory
prefix/man
Here is a sample execution of the configure script, which creates a Samba 2.2.6 makefile for the Linux
platform. Note that you must run the configure script in the source directory and that we are showing you
yet another way to capture the output of the script:
$cd samba-2.2.6/source/
$su
Password:
#./configure --with-smbwrapper --with-smbmount \
--with-msdfs --with-syslog --with-utmp 2>&1 | tee config.my.log
loading cache ./config.cache
checking for gcc... (cached) gcc
checking whether the C compiler (gcc -O ) works... yes
checking whether the C compiler (gcc -O ) is a cross-compiler... no
checking whether we are using GNU C... (cached) yes
checking whether gcc accepts -g... (cached) yes
...(content omitted)...
Table of Contents
checking configure
summary
Index
configure OKReviews
Reader Reviews
creating
./config.status
Errata
Using Samba, 2nd Edition
creating
include/stamp-h
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
creating Makefile
Publisher: O'Reilly
Pub Date:include/config.h
February 2003
creating
ISBN: 0-596-00256-4
In general,
any message from configure that doesn't begin with the words checking or creating is an
Pages: 556
error; Slots:
it often
1 helps to redirect the output of the configure script to a file so that you can quickly search
for errors, as we did with the tee command earlier. If there was an error during configuration, more
detailed information about it can be found in the config.log file, which is written to the local directory by
theconfigure script, as well as in the config.my.log file, which we created by piping through the tee
command.
These
files Edition
are veryissimilar
in both name
andto
content,
be careful toThis
check
both
of them
for
Using Samba,
Second
a comprehensive
guide
Samba but
administration.
new
edition
covers
error
messages
before
continuing!
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
If the configuration works, you'll see a checkingconfiguresummary message followed by a configure
Samba's new role as a primary domain controller and domain member server, its support for the use of
OK message and four or five file-creation messages. So far, so good.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Using
FLAGS Index
= -O -Iinclude ...
Reviews
Errata
This build includes compiles for both smbd and nmbd and ends in a linking command for bin/nmblookup.
Reader Reviews
For example, here is a sample make of Samba Version 2.2.6 on a Linux server:
Using
Samba,
# make
2>&12nd
| Edition
tee make.log
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Using FLAGS =
-O
Publisher: O'Reilly
-DLOGFILEBASE="/usr/local/samba/va
ISBN: 0-596-00256-4
-DSWATDIR="/usr/local/samba/swat" -DSBINDIR="/usr/local/samba/bin
-O
-DLOGFILEBASE="/usr/local/samba/
-DSWATDIR="/usr/local/samba/swat" -DSBINDIR="/usr/local/samba/b
/usr/local/samba/private/smbpasswd" -DTDB_PASSWD_FILE="/usr/local/samba/private/
smbpasswd.tdb"
Using LIBS = -ldl -lnsl -lpam
Compiling smbd/server.c
Compiling smbd/files.c
Compiling smbd/chgpasswd.c
Compiling smbd/connection.c
Compiling smbd/utmp.c
Compiling smbd/session.c
Compiling smbd/dfree.c
Compiling smbd/dir.c
Table of Contents
...(content Index
omitted)...
Reviews
Reader Reviews
Errata
Using Samba,rpc_server/srv_srvsvc.c
Compiling
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Compiling rpc_server/srv_srvsvc_nt.c
Publisher: O'Reilly
Compiling rpc_server/srv_util.c
Pub Date: February 2003
ISBN: 0-596-00256-4
Compiling
rpc_server/srv_wkssvc.c
Pages: 556
Compiling
rpc_server/srv_wkssvc_nt.c
Slots: 1
Compiling rpc_server/srv_pipe.c
Compiling
rpc_server/srv_dfs.c
Using Samba,
Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Compiling
rpc_server/srv_dfs_nt.c
the SWAT graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Compiling
rpc_server/srv_spoolss.c
Windows NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Compiling rpc_server/srv_spoolss_nt.c
Compiling lib/util_getent.c
Compiling rpc_parse/parse_lsa.c
Compiling rpc_parse/parse_net.c
Compiling rpc_parse/parsen/smbmount
Compiling client/smbmnt.c
Linking bin/smbmnt
Compiling client/smbumount.c
Linking bin/smbumount
Compiling utils/nmblookup.c
Linking bin/nmblookup
If you encounter a problem when compiling, first check the Samba documentation to see if it is easily
fixable. Another possibility is to search or post to the Samba mailing lists, which are given at the end of
Chapter 12 and on the Samba home page. Most compilation issues are system-specific and almost
always easy to overcome.
Now that the files have been compiled, you can install them into the directories you identified with the
command:
# make install
If you happen to be upgrading, your old Samba files will be saved with the extension .old, and you can
go back to that previous version with the command makerevert. After doing a makeinstall, you should
copy the .old files (if they exist) to a new location or name. Otherwise, the next time you install Samba,
the original .old will be overwritten without warning and you could lose your earlier version. If you
configured Samba to use the default locations for files, the new files will be installed in the directories
listed in Table 2-2. Remember that you need to perform the installation from an account that has write
privileges on these target directories; this is typically the root account.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Using Samba,
Directory
2nd Edition
Description
By
David Collier-Brown, Robert Eckstein
Jay Ts
/usr/local/samba
Main ,tree
/usr/local/samba/bin
Publisher: O'Reilly
Binaries
ISBN: 0-596-00256-4
/usr/local/samba/man
Pages: 556
Samba documentation
Slots: 1
/usr/local/samba/private
Samba-encrypted password file
/usr/local/samba/swat
SWAT files
Samba log files, lock files, browse list info, shared memory files, process ID
/usr/local/samba/var
Using Samba, Second Edition
is a comprehensive guide to Samba administration. This new edition covers
files
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical
configuration
tool. Updated
for Windows
and XP,
themain
booktree
alsoasexplores
Throughout
the remainder
of the book,
we occasionally
refer 2000,
to the ME,
location
of the
Samba's
new
role
as
a
primary
domain
controller
and
domain
member
server,
its
support
the use of
/usr/local/samba. In most configurations, this is the base directory of the installed Samba for
package;
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
however, it can vary from system to system.
shared files and printers from Unix clients.
Watch out if you've made /usr a read-only partition. You will want to put the logs,
locks, and password files somewhere else.
Here is the installation that we performed on our machine. You can see that we used /usr/local/samba as
the base directory for the distribution:
#make install 2>&1 | tee make-install.log
Using FLAGS =
-O
-DLOGFILEBASE="/usr/local/samba/va
r" -DCONFIGFILE="/usr/local/samba/lib/smb.conf"
...(content omitted)...
The binaries are installed. You can restore the old binaries (if there
were any) using the command "make revert". You can uninstall the binaries
using the command "make uninstallbin" or "make uninstall" to uninstall
binaries, manpages and shell scripts.
...(content omitted)...
======================================================================
The
SWAT files
have been installed. Remember to read the swat/README
Table of Contents
Index
Reviews
Reader Reviews
Errata
SWAT, you've successfully installed all the files. Congratulations! You now
ByDavid
have
Samba
Collier-Brown
on your
, Robert
system!
Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date:
February 2003Your Installation
2.4.1
Upgrading
ISBN: 0-596-00256-4
Pages:a556
Eventually
new
version of Samba will be released, and you will want to upgrade. This is simple; just
repeat Slots:
the same
steps you used to install your current version. Download the source distribution from the
1
Samba web site and install it, then run the ./configure,make, and makeinstall commands as before.
If you've forgotten which options you used with the configure script, take a look at the
source/config.status file in your previous version's source distribution. The first few lines of this file show
the
options
used
the last
timeis
configure
was run. guide to Samba administration. This new edition covers
Using
Samba,
Second
Edition
a comprehensive
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
When you run the make install command to install your new version, the files of the previous version
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
are replaced with the new ones, and then all you have to do is restart the Samba daemons to get your
Samba's new role as a primary domain controller and domain member server, its support for the use of
new version running. See Section 2.8 later in this chapter for directions on how to do this.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
MANPATH
/usr/local/samba/man
MANPATH_MAP
/usr/local/samba/bin
Table of Contents
Index
Reviews
Reader Reviews
Errata
/usr/local/samba/man
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of
Index
Reviews
1. Check your /etc/services file, and if it does not contain the following line, add it to the end of the
Reader Reviews
file:
Errata
Using Samba,
2nd Edition
swat
901/tcp
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
2. Now for inetdor xinetd.These are "Internet super daemons" that handle starting daemons on
Publisher: O'Reilly
demand, instead of letting them sit around in memory consuming system resources. Most systems
Pub Date: February 2003
useinetd, butxinetd is also used in some versions of Unix, notably the Red Hat Linux (Versions 7
ISBN:
0-596-00256-4
and
newer)
that we use in our examples. You can use the ps command to see which of the two your
Pages:
556
system is running.
Slots: 1
For inetd, add a line to the /etc/inetd.conffile. (Check your inetd.conf manual page to see the exact
format of the inetd.conf file if it differs from the following example.) Don't forget to change the path to
the SWAT binary if you installed it in a different location from the default /usr/local/samba:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
swat
stream tcp nowait root /usr/local/samba/bin/swat swat
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
configuration
tool. Updated
forsending
Windows
ME,(hangup)
and XP, the
book also explores
ThenSWAT
forcegraphical
inetd to reread
its configuration
file by
it a2000,
SIGHUP
signal:
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
and filesystem security on the host Unix system, and accessing
#
/bin/kill
-HUP -a authentication
inetd
shared files and printers from Unix clients.
Notice that we are using a version of the kill command that supports the -a option, so as to allow us to
specify the process by name. On FreeBSD and Linux, you can use the killall command[2] as follows:
[2]
Do not confuse this with the Solaris killall command, which performs part of the system shutdown sequence!
0:00 inetd
service swat.
{
socket_type
= stream
wait
= no
protocol
= tcp
only_from
= localhost
user
= root
Table of Contents
Index
log_on_failure
Reviews
server
Reader Reviews
+= USERID
= /usr/local/samba/bin/swat
Errata
port
Using Samba,
2nd Edition
= 901
disable
= no
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Thenxinetd
needs to be sent a signal [3] to make it reread its configuration files:
Pages: 556
[3]
Depending on the version of xinetd you have and how it was compiled, you might need to send a USR1 or some
Slots: 1
other signal rather than the HUP signal. Check the manual page for xinetd (8) on your system for details.
Table of Contents
how to configure
Samba for more complicated and interesting tasks.
Index
Reviews
The
installation
process does not automatically create an smb.conf configuration file, although several
Reader Reviews
example files are included in the Samba distribution. To test the server software, though, we'll use the
Errata
following file, which you can create in a text editor. It should be named smb.conf and placed in the
Using Samba, 2nd Edition
/usr/local/samba/lib directory:[4]
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
[4]
If you did not compile Samba, but instead downloaded a binary, check with the documentation for the package to
find out where it expects the smb.conf file to be. Or, try running the testparm program and look for the location of
Publisher: O'Reilly
smb.conf in the first line of output. If Samba came preinstalled with your Unix system, an smb.conf file is probably
Pub
Date: February
2003on your system.
already
somewhere
ISBN: 0-596-00256-4
[global]
Pages: 556
Slots: 1
workgroup = METRAN
[test]
Usingcomment
Samba, =Second
Edition is
a comprehensive
guide to Samba administration. This new edition covers
For testing
only,
please
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
path graphical
= /usr/local/samba/tmp
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
read NT/2000/XP
only = no authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
guest ok = yes
This brief configuration file tells the Samba server to offer the /usr/local/samba/tmp directory on the
server as an SMB share called test. The server also becomes part of the METRAN workgroup, of which
each client must also be a part. If you have already chosen a name for your own workgroup, use the
name of your workgroup instead of METRAN in the previous example. In case you are connecting your
Samba system into an existing network and need to know the workgroup name, you can ask another
system administrator or go to a Windows system in the workgroup and follow these instructions:
Windows 95/98/Me/NT: open the Control Panel, then double-click the Network icon. Click the
Identification tab, and look for the "Workgroup:" label.
Windows 2000: open the Control Panel and double-click the System icon. Click the Network
Identification tab. The workgroup name will appear below the computer name.
Windows XP: open the Control Panel in Classic View mode and double-click the System icon. Then
click the Computer Name tab.
We'll use the [test] share in the next chapter to set up the Windows clients. For now, you can complete
the setup by performing the following commands as root on your Unix server:
#mkdir /usr/local/samba/tmp
#chmod 777 /usr/local/samba/tmp
You might also want to put a file or two in the /usr/local/samba/tmp directory so that after your Windows
systems are initially configured, you will have something to use to check that everything works.
We should point out that in terms of system security, this is the worst setup possible. For the moment,
however, we only wish to test Samba, so we'll leave security out of the picture. In addition, we will
encounter some encrypted password issues with Windows clients later on, so this setup will afford us the
least amount of headaches.
Table of
Index
[global]
Reviews
Reader Reviews
Errata
In addition, you must use the smbpasswd program (typically located in the directory
By
David Collier-Brown, Robert
, Jayusername/password
Ts
/usr/local/samba/bin/
) to Eckstein
enter the
combinations of the Samba users into Samba's
encrypted password database. For example, if you wanted to allow Unix user steve to access shares
from
a client
system, you would use this command:
Publisher:
O'Reilly
Pub Date: February 2003
#smbpasswd -a steve
ISBN: 0-596-00256-4
New
Pages:
556
SMB
password:
Slots: 1
After logging in, click the GLOBALS button at the top of the screen. You should see the Global Variables
page shown in Figure 2-2.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
In this example, notice that SWAT retrieved the workgroup name from the smb.conf file that you created.
(If it didn't, go back and perform that step correctly.) Make sure that the security field is set to USER.
If you are running Samba 2.2 and your Windows clients are at least Windows 98 or Windows NT 4 SP 3
or later versions, find encryptpasswords in the Security Options section and select yes.
The only other option you need to change from the menu is one determining which system on the LAN
resolves NetBIOS addresses; this system is called the WINS server. At the very bottom of the page, set
thewinssupport field to Yes, unless you already have a WINS server on your network. If you do, put
the WINS server's IP address in the winsserver field instead. Then return to the top of the screen, and
press the Commit Changes button to write the changes out to the smb.conf file.
Next, click the SHARES icon. You should see a page similar to Figure 2-3. Select test (to the right of the
Choose Share button), and click the Choose Share button. You will see the Share Parameters screen, as
shown in Figure 2-3, with the comment and path fields filled in from your smb.conf file.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
If you specified that you want to use encrypted passwords on the GLOBALS page, click the PASSWORD
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
button. Near the top of the screen, you will see the Server Password Management section. Enter your
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Unix username and password in the spaces, and click the Add New User button. This functions the same
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
as the smbpasswd utility and creates an entry in the /usr/local/samba/private/smbpasswd file to allow
Samba's new role as a primary domain controller and domain member server, its support for the use of
you to authenticate from a Windows client.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files
and
printers
from
Unix
clients.
Now
click
the
VIEW
button
at the
top,
and SWAT shows you the following smb.conf file:
# Samba config file created using SWAT
# from localhost (127.0.0.1)
# Date: 2002/09/05 04:56:43
# Global parameters
workgroup = METRAN
encrypt passwords = Yes
wins support = Yes
[test]
comment = For testing only!
path = /usr/local/samba/tmp
read only = No
Once this configuration file is completed, you can skip the next step because the output of SWAT is
guaranteed to be syntactically correct.
Table of Contents
[global]
Index
Reviews
oplocks Reader
= no Reviews
Errata
That is, use a text editor to add the line oplocks=no to the [global] section of your smb.conf file. With
Using Samba, 2nd Edition
this example, as with other examples we will present throughout this book, you do not need to enter the
By
David Collier-Brown
Eckstein
, Jay Ts
[global]
line again,Robert
in your
configuration
file. We include it only to indicate in which section the
parameter belongs.
Publisher: O'Reilly
ThePub
oplocks
=no parameter
disables opportunistic locking by clients. This will result in significantly
Date: February
2003
poorerISBN:
performance,
but
will
help ensure that flaky Windows clients and/or unreliable network hardware
0-596-00256-4
will not lead to corrupted files on the Samba server.
Pages: 556
1
We willSlots:
cover
opportunistic locking (oplocks) in more detail in the section "Locks and Oplocks" in Chapter
8, and recommend that you understand the ideas presented there before implementing a production
Samba server that serves database files or other valuable data.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
2.6.4
Testing the Configuration File
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
If
you didn't
use SWATauthentication
to create yourand
configuration
you should
probably
it to ensure
that it is
Windows
NT/2000/XP
filesystem file,
security
on the host
Unixtest
system,
and accessing
syntactically
correct.
It
might
seem
silly
to
run
a
test
program
against
an
eight-line
configuration
file, but
shared files and printers from Unix clients.
it's good practice for the real ones that we'll be writing later on.
The test parser, testparm, examines an smb.conf file for syntax errors and reports any it finds along with
a list of the services enabled on your machine. An example follows; you'll notice that in our haste to get
the server running we mistyped workgroup as workgrp (the output is often lengthy, so we recommend
capturing it with the tee command):
Load smb config files from smb.conf
Unknown parameter encountered: "workgrp"
Ignoring unknown parameter "workgrp"
Processing section "[test]"
Loaded services file OK.
Press Enter to see a dump of your service definitions
# Global parameters
[global]
workgroup = WORKGROUP
netbios name =
netbios aliases =
server string = Samba 2.2.6
interfaces =
bind interfaces only = No
...(content omitted)...
Table of Contents
[test]
Index
Reviews
comment Reader
= For Reviews
testing only!
Errata
Usingpath
Samba,
= 2nd
/usr/local/samba/tmp
Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
read only = No
O'Reilly
ThePublisher:
interesting
parts are at the top and bottom. The top of the output will flag any syntax errors that you
Pub
Date:
February
2003 the bottom lists the services that the server thinks it should offer. A word of
might have made, and
0-596-00256-4
advice:ISBN:
make
sure you and the server have the same expectations.
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Port
137
Index
Reviews
Errata
Using Samba,
2ndNetBIOS
Edition
Used for
name service
ByDavid
Port
139
Collier-Brown, Robert Eckstein, Jay Ts
Used for file and printer sharing and other operations
Publisher: O'Reilly
Port 445
Pub Date: February 2003
ISBN: 0-596-00256-4
Used
by Windows 2000/XP when NetBIOS over TCP/IP is disabled
Port
Pages: 556
901
Slots: 1
Used by SWAT
At the minimum, your organization's Internet firewall should shut down all the ports in the list to traffic in
both directions. Do not assume that preventing incoming connections is sufficient; there are cracks that
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
trick Windows clients into sending data out of the local area network and into the Internet by SMB
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
protocol, even from a local network that uses private IP addresses not forwarded by routers. If you want
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
SMB traffic to travel across the Internet to remote sites, the best way is to use a virtual private network
Samba's new role as a primary domain controller and domain member server, its support for the use of
(VPN). See the O'Reilly book, Virtual Private Networks, for more information on this subject.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and
printers
from
clients.
In addition,
you might
wish
to Unix
configure
a firewall on the Samba host system to keep SMB packets from
traveling further than necessary within your organization's network. For example, port 901 can be shut
down for remote accesses so that SWAT can be run only on the Samba host system. If you are using
Samba to serve only a fraction of the client systems within your organization, consider allowing SMB
packets (i.e., packets on ports 137-139 and 445) to go to or come from only those clients.
For more information on configuring firewalls, see the O'Reilly book Building Internet Firewalls.
Table of Contents
ManuallyIndex
Reviews
Errata
Frominetd
or xinetd
#/usr/local/samba/bin/smbd
-D
Slots: 1
#/usr/local/samba/bin/nmbd -D
Samba will now be running on your system and is ready to accept connections. However, keep in mind
Using
Editionexit
is a for
comprehensive
guide to Samba
new to
edition
that if Samba,
either ofSecond
the daemons
any reason (including
systemadministration.
reboots), they This
will need
be covers
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as well as
restarted manually.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
2.8.2
Startup
shared Automatic
files and printers
from Unix clients.
To have the Samba daemons started automatically when the system boots, you need to add the
commands listed in the previous section to your standard Unix startup scripts. The exact method varies
depending on the flavor of Unix you're using.
to get away with making a simple change to an rc.local file as with BSD Unix, but System V typically uses
directories containing links to scripts that control daemons on the system. Hence, you need to instruct
the system how to start and stop the Samba daemons. The first step to implement this is to modify the
contents of the /etc/rc.d/init.d directory by adding something similar to the following shell script, which
for this example we will name smb:
#!/bin/sh
Table of Contents
Check thatIndex
#
the Samba configuration file exists
Reviews
[
] || exit 0
-f /usr/local/samba/lib/smb.conf
Reader Reviews
Errata
start(
{
Publisher: O'Reilly
Pub Date: February 2003
ISBN:
echo
0-596-00256-4
-n "Starting
Pages: 556
/usr/local/samba/bin/smbd
Slots:
1
-D
ERROR=$?
echo
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
echo -n "Starting NMB services: "
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
/usr/local/samba/bin/nmbd -D
ERROR2=$?
if [ $ERROR2 -ne 0 ]
then
ERROR=1
fi
echo
return $ERROR
}
stop(
{
echo -n "Shutting down SMB services: "
/bin/kill -TERM -a smbd
ERROR=$?
echo
ERROR2=$?
Table of Contents
Index
if [Reviews
$ERROR2 -ne 0 ]
Reader Reviews
thenErrata
ERROR=1
fi
Publisher: O'Reilly
Pub Date:
February 2003
echo
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
return $ERROR
}
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
case "$1" in
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
start)
shared files and printers from Unix clients.
start
;;
stop)
stop
;;
*)
echo "Usage: $0 {start|stop}"
exit 1
esac
exit $?
With this script, you can start and stop smbd and nmbd like this:
#/etc/rc.d/init.d/smb start
Starting SMB services:
Starting NMB services:
0:00 /usr/local/samba/bin/smbd -D
1270 ?
0:00 /usr/local/samba/bin/nmbd -D
1465 pts/2
#/etc/rc.d/init.d/smb stop
Table of Contents
Index
Shutting
down
SMB services:
Reviews
Shutting
down
Reader
NMB Reviews
services:
Errata
If youSamba,
are having
trouble writing a startup script for your system, check to see if there is a packaged
Using
2nd Edition
release of Samba (available from your Unix vendor or the Samba FTP site). If so, you might be able to
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
extract a startup script from it to use as a starting point. Typically, this script doesn't change much (if at
all) from release to release, so using a script from an older Samba version should not be a problem.
Publisher:
O'Reilly is to check the packaging directory in the Samba source distribution. In that directory,
Another
possibility
Pubare
Date:
February 2003 for many Unix versions in which you can find a startup script for those versions.
there
subdirectories
Even ifISBN:
your0-596-00256-4
version isn't included, you can probably find a startup script for a similar version to use as a
starting
point.
Pages:
556
Slots: 1
Finally, we need to add symbolic links to the smb script in the /etc/rc.d/rcX.d directories:
#ln -s /etc/rc.d/init.d/smb /etc/rc.d/rc3.d/S35smb
Using
Second Edition is a/etc/rc.d/rc5.d/S35smb
comprehensive guide to Samba administration. This new edition covers
#ln -sSamba,
/etc/rc.d/init.d/smb
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP authentication
and filesystem security on the host Unix system, and accessing
#
ln -s /etc/rc.d/init.d/smb
/etc/rc.d/rc0.d/K35smb
shared files and printers from Unix clients.
#ln -s /etc/rc.d/init.d/smb /etc/rc.d/rc1.d/K35smb
#ln -s /etc/rc.d/init.d/smb /etc/rc.d/rc2.d/K35smb
#ln -s /etc/rc.d/init.d/smb /etc/rc.d/rc4.d/K35smb
#ln -s /etc/rc.d/init.d/smb /etc/rc.d/rc6.d/K35smb
The first two commands, with link names starting with an "S", cause Samba to be started when entering
runlevels 3 or 5, which are the runlevels in which network file sharing (NFS) is normally enabled. The
second group of commands, with link names starting with a "K", cause Samba to be shut down when
entering any of the other runlevels (0, 1, 2, 4, or 6).
The links starting with "S" are used to start the daemons, and the links starting with "K" are used for
killing them. When the runlevel is changed, the links starting with "K" in the corresponding directory
(e.g., the rc3.d directory for runlevel 3) are executed, followed by the links starting with "S". If we
wanted, we could have Samba restarted when switching between runlevels 3 and 5 by adding a K35smb
link to each rc3.d and rc5.ddirectory.
The number after the K or S in the link names is used to set the order in which all the daemons with links
in the directory are started or killed off. Get a long listing of the rc3.d or rc5.d directories to see how this
is set up on your system. We use 35 to match the behavior of Red Hat's Samba RPM package. The
important thing is to make sure when starting Samba that all services it requires are started before it.
When shutting down, it is a good idea to shut down Samba before services it requires to avoid excess
error messages in the log files, but the order is not as crucial.
[5]
The Samba daemons are started during system boot by the script
/System/Library/StartupItems/Samba/Samba . To trigger the execution of this script, edit the file
/etc/hostconfig and change the SMBSERVER parameter to look like this:
SMBSERVER=-YESOn Mac OS X, the graphical user interface (GUI) provides an alternative to using the command line.
Table ofPreferences
Contents
Launch the System
application, and select Sharing (see Figure 2-4). Under the Services tab,
Index
turn on Windows File Sharing. This will make the aforementioned change to /etc/hostconfig and
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
If you decide to install Samba yourself on Mac OS X, it's best not to stomp on the installation provided
with the OS. Use the procedures detailed earlier in this chapter to install the software into
/usr/local/samba or some other area unaffected by OS upgrades. (Remember to set up users with
smbpasswd if you're using encrypted passwords, as described earlier in this chapter. This step is handled
automatically with entries in /var/db/samba/hash if you're using the built-in server on Mac OS X.) Once
you've got that working, you can edit the Samba startup item script to refer to your installation, like this:
#!/bin/sh
# Start Samba
. /etc/rc.common
if [ -f /usr/local/samba/lib/smb.conf ]; then
/usr/local/samba/bin/smbd -D
/usr/local/samba/bin/nmbd
-D
Table
of Contents
Index
fi
fi
Reviews
Reader Reviews
Errata
However, beware of OS updates, which can wipe out your changes. One solution is to make the script
By
David Collier-Brown
, Robert Eckstein, Jay Ts
immutable,
like this:
#chflags
Publisher:uchg
O'Reilly/System/Library/StartupItems/Samba/Samba
Pub Date: February 2003
2.8.2.4ISBN:
Testing
automatic startup
0-596-00256-4
Pages: 556
If you Slots:
can afford
a few minutes of downtime, reboot your system and again use the ps command to
1
check that the smbd and nmbd daemons are running. And if you are managing a 24/7 server, we highly
recommend that you find some downtime in which to reboot and perform this check. Otherwise, your
next unscheduled downtime might surprise you with a mysterious absence of SMB networking services
when
system
comes
up again!
Using the
Samba,
Second
Edition
is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role as
a primary
2.8.3
Starting
from
inetddomain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files
printers
clients.
[6]and
Theinetd
daemon
is afrom
UnixUnix
system's
Internet "super daemon." It listens on ports defined in
/etc/services and executes the appropriate program for each port, which is defined in /etc/inetd.conf. The
advantage of this scheme is that you can have a large number of daemons ready to answer queries, but
they don't all have to be running all the time. Instead, inetd listens for connection requests and starts the
appropriate daemon when it is needed. The penalty is a small overhead cost of creating a new daemon
process, as well as the fact that you need to edit two files rather than one to set things up. The inetd
daemon is handy if you have only one or two Samba users or your machine is running too many
daemons already. It's also easier to perform an upgrade without disturbing an existing connection.
[6]
With early releases of Samba 2.2, there were reports of intermittent errors when starting from inetd. We provide
this information so that it will be available for later releases when the problem will hopefully have been identified and
corrected.
If you wish to start from inetd, first open /etc/services in your text editor. If you don't already have them
defined, add the following two lines:
netbios-ssn
139/tcp
netbios-ns
137/udp
Next, edit /etc/inetd.conf. Look for the following two lines and add them if they don't exist. If you already
havesmbd and nmbd lines in the file, edit them to point at the new smbd and nmbd you've installed. Your
brand of Unix might use a slightly different syntax in this file; use the existing entries and the inetd.conf
manual page as a guide:
netbios-ssn stream tcp nowait root /usr/local/samba/bin/smbd smbd
netbios-ns
dgram
udp wait
Finally, kill any smbd or nmbd processes and send the inetd process a hangup (HUP) signal to tell it to
reread its configuration file:
Table
xinetd,
of Contents
you will need to supply a configuration file in the /etc/xinetd.d directory.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
#
-U% -L localhost
/usr/local/samba/bin/smbclient
Index
Reviews
Reader Reviews
Errata
Sharename
Publisher:
O'Reilly
Type
Comment
----
-------
test
Disk
IPC$
IPC
--------ISBN:
0-596-00256-4
Pages: 556
Slots: 1
ADMIN$
Disk
IPC Service (Samba 2.2.6)
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new
role as a primary domain
controller and domain member server, its support for the use of
Server
Comment
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files
and printers from Unix------clients.
--------TOLTEC
Workgroup
Master
---------
-------
METRAN
TOLTEC
If there is a problem, don't panic! Try to start the daemons manually, and check the system output or the
debug files at /usr/local/samba/var/log.smb to see if you can determine what happened. If you think it
might be a more serious problem, skip to Chapter 12 for help on troubleshooting the Samba daemons.
If it worked, congratulations! You now have successfully set up the Samba server with a disk share. It's a
simple one, but we can use it to set up and test the Windows 95/98/Me and NT/2000/XP clients in the
next chapter. Then we will start making it more interesting by adding services such as home directories,
printers, and security, and by seeing how to integrate the server into a larger Windows domain.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
Index
Reader Reviews
For
each Windows
version, these are the main issues we will be dealing with:
Reviews
Errata
Making sure
required networking components are installed and bound to the network adapter
Configuring
networking
with,Jay
a valid
ByDavid
Collier-Brown
, Robert Eckstein
Ts
servers
Publisher: O'Reilly
ISBN: 0-596-00256-4
Setting
the username(s) and password(s)
Pages: 556
In addition,
Slots: 1some minor issues involving communication and coordination between Windows and Unix are
different among Windows versions.
One can go crazy thinking about the ways in which Unix is different from Windows, or the ways in which
members of the Windows family are different from each other in underlying technology, behavior, or
Using
Samba,For
Second
Edition
a comprehensive
guide to
Samba
This
new edition
covers
appearance.
now let's
justisfocus
on their similarities
and
see if administration.
we can find some
common
ground.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
3.1.1
Components
Windows
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Unix systems historically have been monolithic in nature, requiring recompilation or relinking to create a
kernel with a customized feature set. However, modern versions have the ability to load or unload device
drivers or various other operating-system features as modules while the system is running, without even
needing to reboot.
Windows allows for configuration by installing or uninstalling components. As far as networking goes,
components can be one of three things:[1]
[1]
We are intentionally omitting device drivers because they are hardware-specific, and we assume you are getting
installation directions from the manufacturer.
Protocols
Clients
Services
Since Samba works using the TCP/IP protocol, of course we'll want to have that installed. In some cases,
we also will want to find protocols to uninstall. For example, if Netware protocol (IPX/SPX) is not required
on the network, it might as well be removed.
NetBEUI protocol should be removed if possible. Having NetBEUI running at the same time as NetBIOS
over TCP/IP causes the system to look for services under two different protocols, only one of which is
likely to be in use. When Windows is configured with one or more unused protocols, 30-second delays will
result when Windows tries to communicate with the unused protocol. Eventually, it times out and tries
another one, until it finds one that works. This fruitless searching results in terrible performance.
The other two items in the list, client and service components, are pretty much what you'd expect. Client
components perform tasks related to connecting with network servers, and service components are for
making the local system into a server of resources on the network. In Chapter 1 we told you that SMB
systems can act as both clients and servers, offering resources on the network at the same time they
request resources. In accordance with that, it is possible to install a component for SMB client services
and, separately, a service component that allows file and printer shares on the local system to be
accessible from other systems on the network.
3.1.1.1 Bindings
Once a networking component is installed, it must be bound to a hardware interface, or adapter, to be
used
on the network.
At first this might seem like an odd complication; however, it is a conceptual model
Table of Contents
that
allows
the
associations
between hardware and software to be clearly displayed and easily modified
Index
through
a
graphical
interface.
Reviews
Reader Reviews
We will want to make sure that your Windows client has both TCP/IP and the client component for SMB
Errata
networking installed
and also that it is bound to the network adapter that connects to our Samba
Using Samba, 2nd Edition
network, which in most cases will be an Ethernet adapter.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher:
O'Reilly
3.1.2
IP Address
Pub Date: February 2003
ISBN:
Just like
any0-596-00256-4
Unix system (or any other system that is using TCP/IP), your Windows systems will need an
Pages:
IP address. 556
If you are using DHCP on your network, you can configure Windows to obtain its IP address
automatically
Slots: 1 by using a DHCP server. Otherwise, you will need to assign a static IP address manually
along with a netmask.[2]
[2]
Make sure to use the same netmask as all other systems on the network. You can find the netmask in use by
checking with Unix or Windows systems that have already been configured.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all you
versions
ofaSamba
2.0 to
2.2, you
including
features
from an
alpha
of 3.0, you
as well
If
are on
privatefrom
network
where
have selected
the authority
to assign
your
ownversion
IP addresses,
canas
[3]for Windows 2000, ME, and XP, the book also explores
the SWAT
configuration
tool.ranges:
Updated
select
fromgraphical
addresses
in one of three
Samba's new role as a primary domain controller and domain member server, its support for the use of
[3] Keep in mind that IP addresses ending in .0 are reserved for network addresses and that ones ending in .255 are for
Windows
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
broadcast
addresses.
be assigned to any system on the network.
shared
files and
printersThese
fromshould
Unix never
clients.
10.0.0.1 through 10.255.255.254
172.16.0.1 through 172.31.255.254
192.168.0.1 through 192.168.255.254
These address ranges are reserved for private networks not directly connected to the Internet. For more
information on using these private network addresses, see RFC 1918.
If you're not maintaining your own separate network, see your system administrator for some available
addresses on your network, as well as for the proper netmask to use.
You should also be prepared to enter the IP address of the default gateway for the network. In some
networks, the default gateway is the system or router that connects the LAN to the Internet. In other
cases, the default gateway connects a subnet into a larger departmental or enterprise network.
Although the specific implementation is different, name resolution in Windows is also performed by
querying a number of resources, some of which are similar (or even identical) to their Unix counterparts.
Table of Contents
servers
for
your
Windows
system to use, it might still resort to broadcast name resolution if it is
Index
unsuccessful
at
querying
the
name servers. For this reason, we recommend that you provide multiple
Reviews
reliable name servers for your Windows computers on the network.
Reader Reviews
[4]
Errata
To be more
explicit about this, the system will identify itself to the network as a b-node rather than an h-node.
If
that weren't
enough
to Eckstein
get you,Jay
interested
in setting up WINS and DNS servers, broadcast name
ByDavid
Collier-Brown
, Robert
Ts
resolution is usually limited to working on the local subnet because routers are usually configured not to
forward broadcast packets to other networks.
Publisher: O'Reilly
We've already told you about WINS in Chapter 1, and we don't have much more to say about it here.
WINS can translate simple NetBIOS computer names such as huastec or navajo into IP addresses, as
required on an SMB network. Of course, the interesting thing here is that Samba can act as a WINS
server if you include the line:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
wins
support
= yes from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
in
your Samba
new role
server's
as a primary
smb.conf
domain
file. This
controller
can be and
a good
domain
thing,
member
to be sure,
server,
andits
wesupport
highly recommend
for the use of
it.
Windows
Not
only will
NT/2000/XP
you have authentication
a reliable WINSand
server
filesystem
to reduce
security
the number
on the host
of broadcast
Unix system,
packets,
and but
accessing
you won't
shared
need
tofiles
run and
Windows
printers
NT/2000/XP
from Unixto
clients.
get it.
One caveat about using Samba as a WINS server is that Samba (up to Version 2.2,
at least) cannot synchronize with other WINS servers. So if you specify a Samba
server as your Windows system's WINS server, you must be careful not to specify
any additional (i.e., secondary) WINS servers. If you do, you are likely to run into
problems because the servers will not be able to synchronize their databases with
each other. In Samba's defense, if you are using a Samba WINS server (running
on a typically reliable Unix host), you will probably have little need for a secondary
WINS server anyway.
3.1.3.3 LMHOSTS
All Windows versions support a backup method of name resolution, in the form of a file called LMHOSTS
[5] that contains a lookup table of computer names and IP addresses. This exists for "historical
purposes," and is a rather awkward method of name resolution because it requires the administrator
(i.e., you!) to keep copies of LMHOSTS up to date on every single Windows system on the network. To be
fully effective, LMHOSTS would have to be updated every time a new system were added to (or removed
from) the network. Of course, there might be ways to automate that process, but a better option would
be simply to run a WINS name server that is intentionally designed to solve that specific problem.
[5]
We put the names of the LMHOSTS and HOSTS files in uppercase for additional clarityto remind you that we are
referring to the files on Windows rather than on Unix, and because that's the way we see them in other books on
Windows. The case of the letters in the two names actually does not matter.
There are perhaps a couple of reasons why you might want to bother with LMHOSTS files. In rare
situations, there might be no WINS server on the network. Or maybe a WINS server exists, but it's
unreliable. In both cases, if the Windows system has a valid LMHOSTS file, it can help to avoid your
network bogging down from those dreaded broadcast name queries.
The format of the LMHOSTS file is simple and similar to the /etc/hosts file with which you might be
familiar from running Unix systems. Here are the contents of a sample LMHOSTS file:
172.16.1.1
toltec
172.16.1.2
aztec
172.16.1.3
mixtec
172.16.1.4
Table zapotec
of Contents
Index
172.16.1.5
huastec
Reviews
Reader Reviews
172.16.1.6
Erratamaya
172.16.1.7
olmec
172.16.1.8
chichimec
Publisher: O'Reilly
Pub Date: February hopi
2003
172.16.1.11
ISBN: 0-596-00256-4
172.16.1.12
Pages: 556
zuni
Slots: 1
172.16.1.13
dine
172.16.1.14
pima
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
172.16.1.15
apache
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
172.16.1.21
inca
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
172.16.1.22
qero
shared files and printers from Unix clients.
As you can see, the format is like that of /etc/hosts, except that instead of an FQDN (e.g.,
toltec.metran.cx), only a NetBIOS computer name (toltec) is given. One way to create an LMHOSTS
file for your Windows systems is to copy a /etc/hosts file and edit out the parts you don't need. This will
work great if your network doesn't have a DNS (or NIS) name server and the Unix system is dependent
on/etc/hosts for its own name service. But if your Unix system is querying a DNS server (which is the
most frequent case on anything larger than the very smallest networks), you would be better advised to
look in the DNS server's configuration files for your source of computer names and IP addresses.
If you do not have administrative access to your network's DNS server, you might be able to use tools
such as nslookup,nmap, and dig to query the server and obtain the information you need.
3.1.3.4 DNS
TheDNS is responsible for translating human-readable, Internet-style hostnames such as
pima.metran.cx or sales.oreilly.com into IP addresses.
On your first reading of this section, you might be wondering what a section on DNS is doing in a book
about NetBIOS and SMB networking. Remember, we told you that Windows can use more than WINS
(NetBIOS Name Service) in its strategy for performing name resolution. Because DNS is also able to
supply IP addresses for simple hostnames (which are usually the same as NetBIOS computer names), it
can be helpful to configure Windows to know about a DNS server on your network. This is slightly more
important for newer Windows versions than older ones, and more so for Windows NT/2000/XP than for
Windows 95/98/Me, because nowadays Microsoft is focusing more on TCP/IP as the standard protocol
and DNS as the primary name service.
To find the address of your DNS server, look at the file /etc/resolv.conf on your Samba server or any
other Unix system on the local network that is using DNS. It looks like the following:
#resolv.conf
domain metran.cx
nameserver 127.0.0.1
nameserver 172.16.1.53
In this example, the first name server in the list is 127.0.0.1, which indicates that the Samba server is
also a DNS server for this LAN.[6] In that case, you would use its network IP address (not 127.0.0.1, its
localhost
address)
your DNS server when configuring Windows. Otherwise, use the other addresses
Table for
of Contents
you
find
in
the
lines
beginning
with nameserver. Try to select ones on your own network. Any name
Index
servers
listed
in
/etc/resolv.conf
should work, but you'll get better performance by using a server nearby.
Reviews
Reader Reviews
The address 127.0.0.1 is known as the localhost address and always refers to itself. For example, if you type ping
Errata
127.0.0.1
on a Unix server, you should always get a response, because you're pinging the host itself.
[6]
AllDavid
By
versions
Collier-Brown
of Windows
, Robert
can
Eckstein
be configured
, Jay Ts
to know of multiple domain name servers, and you might wish
to take advantage of this for increased reliability. If the first domain name server does not respond,
Windows
can
try others in its list.
Publisher:
O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
3.1.3.5
HOSTS
Pages: 556
Slots: 1
Similar to how the LMHOSTS file can be added to supplement WINS, the HOSTS file on a Windows
system can be optionally added to supplement DNS name resolution. Most of our comments regarding
LMHOSTS also apply here.
Using
Samba,
SecondofEdition
comprehensive
guide
administration.
This new
edition
This time
the format
the fileisisanot
just similar to
that to
of Samba
/etc/hosts
found on Unixthe
format
is covers
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as
exactly the same. You can simply copy /etc/hosts from your Samba server or other Unix system towell
the as
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
proper directory on your Windows system.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
and
filesystem
security installation
on the hostdirectory,
Unix system,
and
On
Windows
95/98/Me,
the HOSTS file
goes
in the Windows
which
is accessing
usually
shared files and
printers
Unix hosts.sam
clients.
C:\Windows.
Note
that a from
file called
is already there, which is a sample HOSTS file provided by
Microsoft.
On Windows NT/2000/XP, the HOSTS file goes in the \system32\drivers\etc directory under the Windows
installation directory, which is usually C:\WINNT.
3.1.4 Passwords
Unix systems use username and password pairs to authenticate users either on a local system or in an
NIS domain. Windows NT/2000/XP are very similar; a user supplies his username and password to log on
to the local system or to a Windows domain.
When the SMB network is set up as a workgroup, things are different. There is no domain to log on to,
although shares on the network can be password-protected. In this case, one password is associated with
each password-protected share, rather than with individual users.
Samba's default user-level authentication in a workgroup is different from that of Windows. To access
shares on the Samba host, users are required to supply a valid username and password for an account
on the Samba host. This will be discussed in more detail in Chapter 9.
An unfortunate complication arises with passwords. In the first release of Windows 95 and in Windows NT
4.0 with Service Pack 2 (SP2) or less, as well as in all previous versions of Windows, passwords are
allowed to be sent over the network in plain text. But in Windows 95 with the network redirector
update,[7]
[7]
Windows NT 4.0 SP3 or later, and all subsequent releases of Windows, a registry setting must be
modified to enable plain-text passwords. These more modern versions of Windows prefer to send
encrypted passwords, and if you are working with one of them (and don't want to have to modify the
Table
of Contents
Index
If your first attempt to access a Samba share results in a dialog box asking for a password for IPC$, as
Reviews
shown in Figure 3-1, it is probably because you neglected either or both of these two steps, and the
Reader Reviews
Samba server did not recognize the encrypted password that the Windows system sent to it. Another
possible dialogErrata
box that might come up is the one shown in Figure 3-2, which was presented by a
Using Samba, 2nd Edition
Windows 2000 client.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Windows
2000
logon
error
dialog
Samba's new role as aFigure
primary 3-2.
domain
controller and
domain
member
server,
its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
The rest of this chapter is divided into four sections. The first section covers setting up Windows
95/98/Me computers, and the rest of the sections cover Windows NT 4.0, Windows 2000, and Windows
XP individually. Each section roughly parallels the order in which we've introduced networking concepts in
this section. You need to read only the section that applies to the Windows version with which you are
working, and once you have finished reading it, you can continue at the beginning of the next chapter
where we will start covering more advanced Samba features and networking issues.
Keep in mind that we are continuing our example from Chapter 2, in which we are
setting up a very simple prototype network using a workgroup that has very lax
security. After you have the basics working, we recommend you continue with later
chapters to learn how to implement both better security and a Samba domain.
Table of Contents
Reviews
Reader Reviews
Samba uses TCP/IP to communicate with clients on the network, so you will need to make sure there is
Errata
support for TCP/IP
on each Windows client. Unlike Unix operating systems, Windows does not necessarily
Using Samba, 2nd Edition
have support for TCP/IP installed. However, when Windows is installed on a computer with a network
By
David
, Robert
Jaya Ts
card
or Collier-Brown
a network card
is Eckstein
added ,to
system already running Windows, TCP/IP support is installed by
default, along with the Client for Microsoft Networks, which supports SMB file and printer sharing.
Publisher: O'Reilly
To make sure both services are installed on your Windows system, double-click the Network icon in the
Pub Date: February 2003
Control Panel to open the Network dialog box, as shown in Figure 3-3.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
You should see at least the Client for Microsoft Networks component installed on the system, and
hopefully a networking device (preferably an Ethernet card) bound to the TCP/IP protocol. If there is only
one networking hardware device, you'll see the TCP/IP protocol listed below the device to which it is
bound, as shown in Figure 3-1.
You might also see "File and printer sharing for Microsoft Networks," which is used to make the system
into a server. In addition, you might see NetBEUI or Novell Networking. Definitely remove NetBEUI
unless you are sure you need it, and if you don't have any Novell servers on your network, you can
remove Novell (IPX/SPX) as well. To remove a service, simply click its name and then click the Remove
button.
selecting Protocol and clicking "Add..." on the following dialog box, which should look similar to Figure 34.
Table of Contents
Index
Reviews
Reader Reviews
Errata
After that, select manufacturer Microsoft, then protocol TCP/IP, as shown in Figure 3-3, then click OK.
After
doing O'Reilly
so, you will be returned to the network dialog. Click OK to close the dialog box, and Windows
Publisher:
will Pub
install
the
necessary components from the CD-ROM and request that the system be rebooted. Go
Date: February 2003
ahead and reboot the system, and you're set.
ISBN: 0-596-00256-4
Pages:
Client
for 556
Microsoft
If
Networks is not in the list, you can add it similarly. The only significant difference is
Slots:
that you
are1 adding a client instead of a protocol, so make sure to select "Client" rather than "Protocol"
when asked.
Using Samba,
Second Edition
3.2.1.2
Configuring
TCP/IPis a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT
configuration
tool. Updated
forexample,
Windowsboth
2000,
and XP,
theand
book
also explores
If you
havegraphical
more than
one networking
device (for
anME,
Ethernet
card
a modem
for dialSamba's
new
role
as
a
primary
domain
controller
and
domain
member
server,
its
support
the use
up networking), the protocol to hardware bindings will be indicated by arrows, as shown infor
Figure
3-5.of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Select the TCP/IP protocol linked to the networking device that will be accessing the Samba network. If
you have only one networking device, simply click the TCP/IP item. Now click the Properties button to
open the TCP/IP Properties dialog. You should see something similar to Figure 3-6.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
If you use DHCP on your network to provide IP addresses automatically to Windows systems, select the
"Obtain an IP address automatically" radio button. Otherwise, click the "Specify an IP address" radio
button and enter the client's address and subnet mask in the space provided. You or your network
manager should have selected an address for the client on the same subnet (LAN) as the Samba server.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
This
for Windows
98/Me;
Windows
95 is just a little
different,
having
separate spaces
for the
primary
UsingisSamba,
Second
Edition
is a comprehensive
guide
to Samba
administration.
This new
edition
covers
and
backup of
WINS
server
IP2.0
addresses.
all versions
Samba
from
to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Select
thenew
"Enable
WINS
Resolution"
radio
button,and
anddomain
enter the
WINS server,
server'sits
address
in for
thethe
space
Samba's
role as
a primary
domain
controller
member
support
use of
provided,
then
click
the
Add
button.
Do
not
enter
anything
in
the
Scope
ID
field.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
A bug in Windows 95/98 sometimes causes the IP address of the WINS server to
disappear after the OK button is clicked. This happens only when only a primary
WINS server has been specified. The workaround is to fill in the fields for both
primary and secondary WINS servers, using the same IP address for each.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Also, provide the hostname (which is the same as the NetBIOS computer name) of the Windows
95/98/Me computer and your Internet domain. (You will need to enter the computer name again later,
along with the workgroup. Make sure to enter the same name each time.) You can safely ignore the
Domain
Suffix Second
Search Order
anything related
toto
Samba.
Using Samba,
Editionfield
is a for
comprehensive
guide
Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
3.2.1.6
Samba'sLMHOSTS
new role as file
a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files to
and
printers
from Unix file,
clients.
If
you want
install
an LMHOSTS
it must be placed in your Windows installation directory (usually
C:\Windows). In the same directory, Microsoft has provided a sample LMHOSTS file named lmhosts.sam,
which you might want to look at for further information on the file's format.
Table of Contents
Index
Reviews
Reader Reviews
Errata
You
a check beside Client for Microsoft Networks, indicating that it's using TCP/IP. If you
Usingshould
Samba,have
2nd Edition
have "File and printer sharing for Microsoft Networks" in the dialog, it should also be checked, as shown
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
in Figure 3-10.
Publisher: O'Reilly
Pub Date: February 2003
3.2.2
Setting the Computer Name and Workgroup
ISBN: 0-596-00256-4
Pages: 556
Finally, click the OK button in the TCP/IP configuration dialog, and you'll be taken back to the Network
Slots: 1
Configuration
dialog. Then select the Identification tab, which will take you to the dialog box shown in
Figure 3-11.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
This is where you set your system's NetBIOS name (which Microsoft likes to call "computer name").
Usually, it is best to make this the same as your DNS hostname, if you are going to have one for this
system. For example, if the system's DNS name is huastec.metran.cx, give the computer a NetBIOS
name of huastec on this tab.
You also set your workgroup name here. In our case, it's METRAN, but if you used a different one in
Chapter 2, when creating the Samba configuration file, use that instead. Just don't call it WORKGROUP
(the default workgroup name) or you'll be in the same workgroup as every misconfigured Windows
computer on the planet!
You can also enter a comment string for this computer. See if you can come up with some way of
describing it that will remind you of what and where it is when you see the comment in a list displayed on
another computer. Everyone on the network will be able to see your comment, so be careful not to
include any information that might be useful to crackers.
Finally, click the OK button and follow whatever instructions Windows provides. (You might have to insert
your Windows distribution CD-ROM and/or reboot.)
Table ofpasswords,
Contents
password
database,
if
you
have
not
already done so.) You can use this method to add as many users as
Index
you
want,
so
as
to
allow
more
than
one
user to use the Windows system to gain access to the Samba
Reviews
shares.
Reader Reviews
Errata
If you mistakenly
entered the wrong password or your Unix password changes, you can change your
Using Samba, 2nd Edition
password on the Windows system by going to the Control Panel and double-clicking the Passwords icon.
By
David
, Robert
Eckstein,Properties
Jay Ts
This
willCollier-Brown
bring up the
Passwords
dialog. Click the Change Passwords tab, and you will see the
dialog shown in Figure 3-12. Now click the "Change Windows Password..." button, which will bring up the
Change
Windows
Publisher:
O'Reilly Password dialog box, shown in Figure 3-13. As indicated by the text entry fields in the
dialog,
enter
your old password, and then the new password, and again to confirm it. Click the OK button
Pub Date: February 2003
and then the Close button on the Password Properties dialog box. Reboot or log out, and use your new
ISBN: 0-596-00256-4
password when you log in again.
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Double-clicking
the server name will show the resources that the server is offering to the network, as
shown Slots:
in Figure
1
3-15 (in this case, the test directory).
Double-click the Entire Network icon, and you should see an icon for your workgroup, as shown in Figure
3-17.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Double-clicking the workgroup icon will bring up a window showing every computer in the workgroup,
which
should include your Samba server, as shown in Figure 3-18.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Double-click the Samba server's icon, and you will get a window showing its shared resources (in this
case, the test directory) as shown in Figure 3-19.
If you don't see the server listed, it might be that browsing is not working correctly or maybe the server
is just taking a few minutes to show up in the browse list. In either case, you can click the Start button,
then select "Run...". This will give you a dialog box into which you can type the name of your server and
the share name test in the Windows UNC format \\server\test, as we did in Chapter 1. This should open
a window on the desktop showing the contents of the folder. If this does not work, there is likely a
problem with name resolution, and you can try using the server's IP address instead of its computer
name, like this:
\\172.16.1.1\test
If things still aren't right, go directly to Section 12.2 to troubleshoot what is wrong with the network.
If it works, congratulations! Try copying files to and from the server using the Windows drag-and-drop
functionality. You might be pleasantly surprised how seamlessly everything works.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reviews
3.3.1 BasicReader
Configuration
Errata
This section presents the steps to follow for TCP/IP-related configuration on Windows NT to get it to
By
David Collier-Brown
, Robert
, Jaymore
Ts
cooperate
with Samba.
If Eckstein
you need
details on Windows NT network administration, refer to Craig
Hunt and Robert Bruce Thompson'sWindows NT TCP/IP Network Administration (O'Reilly), an excellent
guide.
Publisher: O'Reilly
Pub Date: February 2003
You should perform the following steps as the Administrator or another user in the Administrators
ISBN: 0-596-00256-4
group.
Pages: 556
Slots: 1
If the protocol is not installed, you need to add it. Click the Add button, which will display the Select
Network Protocol dialog box shown in Figure 3-21. You should immediately see the TCP/IP protocol as
one of the last protocols listed.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Select TCP/IP as the protocol and confirm it. If possible, install only the TCP/IP protocol. If you see
anything
other
than TCP/IP listed in the Protocols tab and it is not a protocol that you need, you can
Publisher:
O'Reilly
remove
it.
If
you
try
to remove a protocol and get an error message saying that the protocol is being
Pub Date: February
2003
used by
another
service,
you need to click the Services tab and remove that service before you can
ISBN: 0-596-00256-4
remove the protocol. For example, to remove the NWLink IPX/SPX Compatible Transport protocol, you
Pages: 556
would need to remove the Client Service for Netware first.
Slots: 1
This service is actually the Microsoft Networking Client, which allows the computer to access SMB
services. The Workstation service is mandatory. The service is installed by default on both Windows NT
Workstation 4.0 and NT Server 4.0. If it's not there, you can install it much like TCP/IP. In this case you
need to click the Add button and then select Workstation Service, as shown in Figure 3-23.
Table of Contents
Index
Reviews
Reader Reviews
Errata
After you've installed the Workstation service, return to the Protocols tab and select the TCP/IP Protocol
ISBN: 0-596-00256-4
entry in
the window. Then click the Properties button below the window. The Microsoft TCP/IP Protocol
Pages:
556
dialog will be
displayed. There are five tabs in the dialog, and you will need to work with four of them:
Slots: 1
IP Address
WINS Address
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
DNS of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role as a primary domain controller and domain member server, its support for the use of
Bindings
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Select the "Specify an IP address" radio button, and enter the computer's IP address and netmask in the
space provided for the proper adapter (Ethernet card). You or your network manager should have
selected an address for the client on the same subnet (LAN) as the Samba server. For example, if the
server's address is 172.16.1.1 and its network mask is 255.255.255.0, you might use the address
172.16.1.13 (if it is available) for the NT workstation, along with the same netmask. If you use DHCP on
your network, select the "Obtain an IP Address from a DHCP server" button instead.
The gateway field refers to a system typically known as a router. If you have routers connecting multiple
networks,
youTable
should
enter the IP address of the one on your subnet. In our example, the gateway
of Contents
happens
to
be
the
same
system as the Samba server, but they do not by any means have to be the
Index
same.
Reviews
Reader Reviews
Errata
3.3.1.3.2
WINS
Address tab
Using Samba,
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Click the WINS Address tab, shown in Figure 3-25, and you can begin to enter information about name
servers. Enter the address of your WINS server in the space labeled Primary WINS Server. If your Samba
Publisher:
O'Reilly WINS service (in other words, you have the line winssupport=yes in the smb.conf
server
is providing
Pub
Date:
February
file of your Samba 2003
server), provide the Samba server's IP address here. Otherwise, provide the address
ISBN:WINS
0-596-00256-4
of another
server on your network.
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
You probably noticed that there is a field here for the network adapter. This field must specify the
Ethernet adapter on which you're running TCP/IP so that WINS will provide name service on the correct
network. For example, if you have both a LAN and a dial-up adapter, make sure you have the LAN's
network card specified here.
The checkboxes in the lower half of the dialog are for enabling two other methods of name resolution that
Windows can incorporate into its name service. Samba doesn't require either of them, but you might
want to enable them to increase the reliability or functionality of name service for your client. See
Chapter 7 for further information on name resolution issues.
If you'd like to use a DNS server, select the Enable DNS for Windows Resolution checkbox. In addition,
you will need to do some configuration to allow the Windows system to find the DNS server, unless
you're using DHCP.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
3.3.1.3.5 Bindings
Now click the Bindings tab, and check the bindings of network hardware, services, and protocols. Set the
"Show Bindings for" field to "all services," and click all the + buttons in the tree. You should see a display
similar to Figure 3-27, which shows that the NetBIOS, Server, and Workstation interface services are
connected to the WINS client running TCP/IP protocol, and that the WINS client is bound to the Ethernet
adapter of the local area network.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
You can safely leave the default values for the remainder of the tabs in the Network dialog box. Click the
Slots: 1
OK button to complete the configuration. Once the proper files are loaded (if any), you might need to
reboot for your changes to take effect.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
3.3.2
Computer
Workgroup
all versions
of Samba Name
from 2.0and
to 2.2,
including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
The
next new
thingrole
youas
need
a primary
to do isdomain
to givecontroller
the system
and
a domain
NetBIOSmember
computer
server,
name.
itsFrom
support
the for
Control
the use
Panel,
of
Windows NT/2000/XP
double-click
the Network
authentication
icon to openand
thefilesystem
Network dialog
security
box.
onThe
the first
hosttab
Unix
in system,
this dialog
andbox
accessing
should be
shared
the
Identification
files and printers
tab, as from
illustrated
Unix clients.
in Figure 3-28.
Here, you need to identify your computer with a name and change the default workgroup to the one you
specified in the smb.conf file of your Samba server. Click the Change button below the two text fields.
This will open an Identification Changes dialog box, where you can set the workgroup and the computer
name, as shown in Figure 3-29.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
You entered the computer name earlier as a DNS hostname while configuring
TCP/IP, so be sure that the two names match. The name you set here is the
NetBIOS name. You're allowed to make it different from the TCP/IP hostname, but
doing so is usually not a good idea. Don't worry that Windows NT forces the
Using Samba, Second
Edition
is a
comprehensive
guide
toall
Samba
Thisenough
new edition
covers
computer
name
and
the workgroup
to be
capitaladministration.
letters; it's smart
to
all versions of Samba
2.0 to
2.2,
including
features
an alpha version of 3.0, as well as
figure from
out what
you
mean
when selected
it connects
to the from
network.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
3.3.3
Adding
a User
shared files and printers from Unix clients.
In all the previous steps, you were logged into your Windows NT system as Administrator or another
user in the Administrators group. To access resources on the Samba server, you will need to have a
username and password that the Samba server recognizes as valid. Generally, the best way to do this is
to add a user to your NT system, with the same username and password as a user on the Samba host
system.
The directions in this section assume that your network is set up as a workgroup. If
you have already set up your network as a domain, as we describe in Chapter 4,
you do not need to follow the instructions here for adding a local user on the
Windows NT client system. Simply log on to the domain from the client using a
username and password in Samba's smbpasswd account database, and continue
with the next section, Section 3.3.4.
To add a new user, open the Start menu, navigate through the Programs submenu to Administrative
Tools (Common), and select User Manager for Domains. Click the User menu and select the first item,
Add User..., shown in Figure 3-30.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
This brings up the New User dialog box shown in Figure 3-31.
Slots: 1
Fill it out as shown, using the username and password that were added in the previous chapter, and
make sure that only the checkbox labeled Password Never Expires is checked. (This is not the default!)
Click the Add button to add the user, and then click the Close button. You should now see your new
account added to the list in the User Manager dialog box.
Now open the Start menu, select Shut Down, and select the "Close all programs and log on as a different
user?" radio button. Click the Yes button, then log in as the user you just added.
Table of Contents
Index
Double-clicking
the server name will show the resources that the server is offering to the network, as
Reviews
shown in Figure
3-33.
In this case, the test directory and the default printer are offered to the Windows
Reader
Reviews
NT
workstation.
Errata
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
If you don't see the server listed, don't panic. Select Run... from the Start menu. A dialog box appears
that allows you to type the name of your server and its share directory in Windows format. For example,
Using
Samba,
Second
Edition isas
a shown
comprehensive
Samba
administration.
This new
edition
you
would
enter
\\toltec\test,
in Figure guide
3-34, to
and
use your
server's hostname
instead
ofcovers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
"toltec".
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Figure 3-34. Opening a shared directory, using the server's NetBIOS name in
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
the UNC
shared files and printers from Unix clients.
This will work even if browsing services are not set up right, which is a common problem. You can also
work around a name-service problem by entering the server's IP Address (such as 172.16.1.1 in our
example) instead of the Samba server's hostname, as shown in Figure 3-35. Go back and check your
configuration, and if things still aren't right, go to Section 12.2 to troubleshoot what is wrong with the
network.
Figure 3-35. Opening a shared directory, using the server's IP address in the
UNC
If it works, congratulations! Try copying files to and from the server by dragging their icons to and from
the folder on the Samba share. You might be pleasantly surprised how seamlessly everything works.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table ofthe
Contents
group.
Index
Reviews
Reader Reviews
3.4.1
Networking
Errata
Components
Using Samba, 2nd Edition
GoDavid
to the
Control Panel
and
double-click
the Network and Dial-up Connections icon. You should see at
By
Collier-Brown
, Robert
Eckstein
, Jay Ts
least one Local Area Connection icon. If there is more than one, identify the one that corresponds to the
network
adapter that is connected to your Samba network. Right-click the Local Area Connection icon,
Publisher: O'Reilly
and click the Properties button. (Or double-click the Local Area Connection icon, and then click the
Pub Date: February 2003
Properties button in the dialog box that comes up.) You should now be looking at the Local Area
ISBN: 0-596-00256-4
Connection Properties dialog box, as shown in Figure 3-36.
Pages: 556
Slots: 1
Figure
3-36. Windows 2000 Local Area Connection Properties dialog
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
First of all, you might want to click the Configure button under the field for the network adapter, to make
sure you see the message "This device is working properly" in the Device status window. If there is a
problem, make sure to correct it before continuing. You should also see the message "Use this device
(enable)" in the Device usage field of the dialog box. Make sure to set it this way if it is not already. Click
OK or Cancel to get back to the Local Area Connection Properties dialog box.
You should see at least the following two components:
Client for Microsoft Networks
Internet Protocol (TCP/IP)
If you do not see either Client for Microsoft Networks or Internet Protocol (TCP/IP) in your list, you will
need to add them. For either, the method is to click the Install... button, click the type of component
(Client or Protocol), and then click the Add... button. Next, click the component you want to add, and
click the OK button. You should see the component added to the list with the others.
Some components should be removed if you see them in the list:
NetBEUI Protocol
NWLink NetBIOS
NWLink IPX/SPX/NetBIOS
Compatible Transport Protocol
Table of Contents
Index
Reader other
Reviews
If you see anything
than TCP/IP listed as a protocol, and it is not a protocol that you need, you can
Errata
remove it. Uninstall NetBEUI, unless you are sure you need it, and the other three if you do not need to
Using
Samba,
2nd Edition
support
Netware.
If you
try to remove a protocol and get an error message saying that the protocol is
being
by another
service,
you
to remove that service before you can remove the protocol. For
By
Davidused
Collier-Brown
, Robert
Eckstein
, Jayneed
Ts
example, to remove the NWLink IPX/SPX Compatible Transport Protocol, you would need to remove the
Client Service for Netware first.
Publisher: O'Reilly
Pub Date: a
February
2003
To remove
component,
click the component in the list, click the Uninstall button, and then click Yes in
ISBN:
0-596-00256-4
the dialog box that pops up. In some cases, Windows might need to reboot to put the change into effect.
Pages: 556
Slots: 1
3.4.2 Bindings
Next to each client, service, or protocol listed in the window in the Local Area Connections Properties
Using
is a comprehensive
to Samba
administration.
This new
edition covers
dialog Samba,
box, youSecond
will seeEdition
a checkbox.
Make sure theguide
checkbox
is checked
for both Client
for Microsoft
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
well as
Networks and Internet Protocol (TCP/IP). The check marks indicate the networking components as
are
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
bound to the network adapter shown at the top of the dialog box.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Now click Internet Protocol (TCP/IP), and then click Properties to open the Internet Protocol (TCP/IP)
Properties dialog box, shown in Figure 3-37.
3.4.3.1 IP address
If you are using DHCP on your network to assign IP addresses dynamically, select the "Obtain IP address
automatically" radio button. Otherwise, select the "Use the following address:" radio button, and fill in the
computer's IP address and netmask in the spaces provided. You or your network manager should have
selected an address for the client on the same subnet (LAN) as the Samba server. For example, if the
server's address is 172.16.1.1 and its network mask is 255.255.255.0, you might use the address
172.16.1.14, if it is available, along with the same netmask. You can also fill in the IP address of the
Table of Contents
default gateway.
Index
Reviews
3.4.3.2
DNS Reader
serverReviews
Errata
In the lower part of the dialog box, click the "Use the following DNS server addresses:" radio button, and
By
Collier-Brown
, Robert
Eckstein
Ts
fillDavid
in the
IP address
of your
DNS,Jay
server.
Now
click the
Advanced... button to bring up the Advanced TCP/IP Settings dialog box, and then click the
Publisher:
O'Reilly
WINS
tab.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
3.4.3.3Slots:
WINS
server
1
Enter the address of your WINS server in the space labeled "WINS addresses, in order of use:". If your
Samba server is providing WINS service (in other words, you have the line winsservice=yes in the
smb.conf file of your Samba server), provide the Samba server's IP address here. Otherwise, provide the
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
address of another WINS server on your network.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Near the bottom of the dialog box, select the radio button labeled "Enable NetBIOS over TCP/IP". Figure
Samba's new role as a primary domain controller and domain member server, its support for the use of
3-38 shows what your Advanced TCP/IP Settings dialog box should look like at this point.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
the network, you will have to do that after file sharing is configured!) Remember to click the Enable
LMHOSTS Lookup checkbox on the WINS Address tab to enable this functionality.
When you are satisfied with your settings for IP Address, WINS Address, and DNS, click the OK buttons
in each open dialog box to complete the configuration. Windows might need to load some files from the
Windows 2000 distribution CD-ROM, and you might need to reboot for your changes to take effect.
3.4.4
Computer
and Workgroup Names
Table of Contents
Index
From
the Control
Panel, double-click the System icon to open the System Properties dialog box. Click the
Reviews
Network
Identification
tab, and your System Properties dialog box will look similar to Figure 3-39.
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
To give your system computer a name and a workgroup, click the Properties button, which will bring up
the Identification Changes dialog box, as in Figure 3-40.
You need to identify your computer with a name and change the workgroup to the one you specified in
thesmb.conf file of your Samba server. Don't worry that Windows forces the computer name and the
workgroup to be all capital letters; it's smart enough to figure out what you mean when it connects to the
network.
Click the More... button to bring up the DNS Suffix and NetBIOS Computer Name dialog box, shown in
Figure 3-41.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher:
O'Reilly
Enter
the DNS
domain name of this computer in the text field labeled Primary DNS Suffix for this
Pub Date: February
2003
computer:,
and then
click OK. You should now see the FQDN of this system underneath the label "Full
ISBN:
0-596-00256-4
computer
name:".
Click the OK button and then reboot when requested to put your configuration
changes
into
effect. Once again, log in using your administrative account.
Pages:
556
Slots: 1
There have been reports of authentication problems with Samba when a username
on a Windows 2000 system is the same as its computer name.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
3.4.5
Adding
graphical
a configuration
Samba-Enabled
tool. Updated
Userfor Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
and
filesystem
security
onas
the
host in
Unix
and accessing
So
far, you
have been authentication
logged into your
Windows
2000
system
a user
thesystem,
Administrators
group. To
shared resources
files and printers
from Unix
clients.
access
on the Samba
server,
you will need a username and password that the Samba server
recognizes as valid. If your administrative account has such a username and password, you can use it,
but you might want to access your system and the network from a nonadministrative user account
instead.
The directions in this section assume that your network is set up as a workgroup. If
you have already set up your network as a domain, as we describe in Chapter 4,
you do not need to follow the instructions here for adding a local user on the
Windows 2000 client system. Simply log on to the domain from the client using a
username and password in Samba's smbpasswd account database, and continue
with the next section, Section 3.4.6.
To add a new user, open the Control Panel, and double-click the Users and Passwords icon to open the
Users and Passwords dialog box, shown in Figure 3-42.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
The first
Pages:
thing
556 to do is make sure the checkbox labeled "Users must enter a user name and password to
use this
computer."
is checked. Next, click the Add... button to bring up the first dialog box of the User
Slots: 1
Wizard, shown in Figure 3-43.
Fill out the fields, using the username of a valid user account on the Samba host, and then click the Next
> button to enter and confirm the user's password. This password must be the same as the user's
password on the Samba host. If you are using encrypted passwords, make sure this username and
password are the same as what you used when you ran the smbpasswd program. Click the Next >
button, which brings up the final dialog box, shown in Figure 3-44.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Pick a group for the user (the default Standard User should do), and click the Finish button. You should
Publisher: O'Reilly
now see your new account added to the list in the Users and Passwords dialog box. Click the OK button
Pub Date: February 2003
to complete the process.
ISBN: 0-596-00256-4
Pages: 556
return
to the
Now
Users and Passwords control panel window, click the Advanced tab, then click on the
Advanced
Click the Users folder in the left side of the Local Users and Groups window that
Slots:button.
1
appears, and then double-click the account you just added in the right side of the window. In the
Properties window that opens, click the checkbox labeled Password never expires. You are done! Click the
OK buttons in all the dialog boxes, and close all open windows.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Open the Start menu, select Shut Down, and select Log off username from the drop-down menu. Click
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the OK button, then log on with the username and password you just added.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared Connecting
3.4.6
files and printersto
from
theUnix
Samba
clients. Server
Now for the big moment. Your Samba server is running, and you have set up your Windows 2000 client
to communicate with it. Double-click the My Network Places icon on the desktop, and then double-click
the Computers Near Me icon to browse the workgroup. You should see your Samba server listed as a
member of the workgroup, as shown in Figure 3-45.
Double-clicking the server name will show the resources that the server is offering to the network, as
shown in Figure 3-46.
Table of Contents
Index
Reviews
Reader Reviews
Errata
In thisSamba,
case,2nd
theEdition
test directory and the default printer are offered to the Windows 2000 workstation. If
Using
you
don't
see
the
server listed, don't panic. Select Run from the Start menu. A dialog box appears that
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
allows you to type the name of your server and its share directory in Windows format. For example, you
would enter \\toltec\test, as shown in Figure 3-47, and use your server's hostname instead of "toltec".
Publisher: O'Reilly
Pub Date: February 2003
Figure 3-47. Opening a shared directory, using the server's NetBIOS name in
ISBN: 0-596-00256-4
the UNC
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
This will work even if browsing services are not set up right, which is a common problem. You can also
work around a name-service problem by entering the server's IP address (such as 172.16.1.1 in our
example) instead of the Samba server's hostname, as shown in Figure 3-48.
Figure 3-48. Opening a shared directory, using the server's IP address in the
UNC
If things still aren't right, go directly to Section 12.2 to troubleshoot what is wrong with the network.
If it works, congratulations! Try copying files to and from the server. You will be pleasantly surprised how
seamlessly everything works. Now that you've finished setting up the Samba server and its clients, you
can proceed to the next chapter.
Contents
mode. If you see
this, click the Switch to Classic View item in the upper-left corner of the window. All of
Index
our directions Reviews
are for using the Control Panel in Classic View mode.
Reader Reviews
You should perform the following steps as the Administrator or another user in the Administrators
Errata
group.
Using Samba, 2nd Edition
3.5.1
Networking Components
Publisher: O'Reilly
Pub Date: February 2003
Go to the Control Panel and double-click the Network and Dial-up Connections icon. You should see at
ISBN: 0-596-00256-4
least one Local Area Connection icon. If there is more than one, identify the one that corresponds to the
Pages:
556
network adapter
that is connected to your Samba network. Right-click the Local Area Connection icon and
Slots:
1
click the
Properties
button. (Or double-click the Local Area Connection icon and then click the Properties
button in the dialog box that comes up.) You should now be looking at the Local Area Connection
Properties dialog box, as shown in Figure 3-49.
Using Samba,Figure
Second Edition
a comprehensive
guide
to Samba administration.
new edition covers
3-49.is The
Local Area
Connection
PropertiesThis
dialog
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
First of all, you might want to click the Configure button under the field for the network adapter to make
sure you see the message "This device is working properly" in the Device status window. If there is a
problem, make sure to correct it before continuing. You should also see the message "Use this device
(enable)" in the Device usage field of the dialog box. Make sure to set it this way if it is not already. Click
OK or Cancel to close this dialog box, then reopen the Local Area Connection Properties dialog box.
You should see at least the following two components:
Client for Microsoft Networks
Table ofifContents
you do not need to support Netware. If you try to remove a protocol and get an
error messageIndex
saying that the protocol is being used by another service, you need to remove that service
Reviews
Protocol, you Reader
would Reviews
need to remove the Client Service for Netware first.
Errata
To
remove a component, click the component in the list, click the Uninstall button, and then click Yes in
Using Samba, 2nd Edition
the dialog box that pops up. In some cases, Windows might need to reboot to put the change into effect.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher:
O'Reilly
3.5.1.1
Bindings
Pub Date: February 2003
0-596-00256-4
Next toISBN:
each
client, service, or protocol listed in the window in the Local Area Connections Properties
Pages:
556
dialog box, you will see a checkbox. Make sure the checkbox is checked for both Client for Microsoft
Slots:
1 Internet Protocol (TCP/IP). The check marks indicate that the networking components are
Networks
and
bound to the network adapter shown at the top of the dialog box.
Using
Second Edition
is a comprehensive guide to Samba administration. This new edition covers
3.5.2Samba,
Configuring
TCP/IP
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Now click Internet Protocol (TCP/IP) and then click Properties to open the Internet Protocol (TCP/IP)
Samba's new role as a primary domain controller and domain member server, its support for the use of
Properties dialog box, shown in Figure 3-50.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
3.5.2.1 IP address
If you are using DHCP on your network to assign IP addresses dynamically, select the "Obtain IP address
automatically" radio button. Otherwise, select the "Use the following address:" radio button, and fill in the
computer's IP address and netmask in the spaces provided. You or your network manager should have
selected an address for the client on the same subnet (LAN) as the Samba server. For example, if the
server's address is 172.16.1.1 and its network mask is 255.255.255.0, you might use the address
172.16.1.12 (if it is available) along with the same netmask. You can also fill in the IP address of the
default gateway.
Table of Contents
Reader Reviews
In
of the dialog box, click the "Use the following DNS server addresses:" radio button, and
the lower part
Index
fill
in
the
IP
address
of your DNS server.
Reviews
Now click the Advanced... button to bring up the Advanced TCP/IP Settings dialog box, and then click the
Errata
WINS tab.
Using Samba, 2nd Edition
Near the bottom of the dialog box, select the radio button labeled Enable NetBIOS over TCP/IP. Figure 351 shows what your Advanced TCP/IP Settings dialog box should look like at this point.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
The
Advanced
TCP/IP
Settings
dialog,
theof WINS
tabas
allFigure
versions 3-51.
of Samba
from
2.0 to 2.2, including
selected
features
from anshowing
alpha version
3.0, as well
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
in each open dialog box (and the Close button in the Local Area Connection Properties dialog box) to
complete the configuration. Windows might need to load some files from the Windows XP distribution CDROM, and you might need to reboot for your changes to take effect.
Table
of Contents
Index
Figure
Reviews
3-52.
The System Properties dialog, showing the Computer Name tab
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
To give your system computer a name and a workgroup, click the Change... button, which will bring up
the Computer Name Changes dialog box, as in Figure 3-53.
You need to identify your computer with a name and change the workgroup to the one you specified in
thesmb.conf file of your Samba server. Don't worry that Windows forces the workgroup to be all capital
letters; it's smart enough to figure out what you mean when it connects to the network.
Click the More... button to bring up the DNS Suffix and NetBIOS Computer Name dialog box, shown in
Figure 3-54.
Figure 3-54. The DNS Suffix and NetBIOS Computer Name dialog
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Enter
the DNS domain name of this computer in the text field labeled Primary DNS Suffix for this
Pub Date: February 2003
computer:, and then click OK. You should now see the FQDN of this system underneath the label Full
ISBN: 0-596-00256-4
computer name: in the Computer Name Changes dialog box. Click the OK button and then reboot when
Pages: 556
requested to put your configuration changes into effect. Once again, log in using your administrative
Slots: 1
account.
There have been reports of authentication problems with Samba when a username
Using Samba, Second
Edition is
comprehensive
guide
administration.
This new edition covers
on a Windows
XPa system
is the same
asto
itsSamba
computer
name.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
3.5.4
Adding a Samba-Enabled User
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
So far, you have been logged into your Windows XP system as a user in the Administrators group. To
access resources on the Samba server, you will need to have a username and password that the Samba
server recognizes as valid. If your administrative account has such a username and password, you can
use it, but you might want to access your system and the network from a nonadministrative user account
instead.
The directions in this section assume that your network is set up as a workgroup. If
you have already set up your network as a domain, as we describe in Chapter 4,
you do not need to follow the instructions here for adding a local user on the
Windows XP client system. Simply log on to the domain from the client using a
username and password in Samba's smbpasswd account database, and continue
with the next section, Section 3.5.5.
To add a new user, open the Control Panel, and double-click the Users Accounts icon to open the User
Accounts window, shown in Figure 3-55.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Click the Create a new account task, which will bring up the window shown in Figure 3-56. Enter the
username, then click the Next > button.
3-56. Entering
username
Using Samba, Second EditionFigure
is a comprehensive
guide to the
Samba
administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
This password must be the same as the user's password on the Samba host. If you are using encrypted
passwords, make sure this username and password are the same as what you used when you ran the
smbpasswd
program.
the
Password button,
and
you're
done adding the
account.
Using Samba,
Second Click
Edition
isCreate
a comprehensive
guide to
Samba
administration.
This
new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Now
open graphical
the Start menu
and click
the Updated
Log Off button.
In the2000,
Log Off
Windows
boxalso
thatexplores
pops up,
the SWAT
configuration
tool.
for Windows
ME,
and XP, dialog
the book
again
click
the
Log
Off
button.
When
Windows
displays
the
login
screen,
click
the
user
you
just
added,
Samba's new role as a primary domain controller and domain member server, its support for the
use of
and
type
in
the
password
to
log
in.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
If there is a My Network Places item in the Start menu at this point, you can save yourself a little time and just click
that. If you don't see it, don't worry; it will appear automatically later.
Now click View workgroup computers in the Network Tasks box at the left of the window. You should see
your Samba server listed as a member of the workgroup. Double-click its icon, and you will see a window
that looks like Figure 3-59.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
If youPages:
don't556
see the server listed in the workgroup, don't panic. Select Run... from the Start menu. A
dialog Slots:
box appears
that allows you to type the name of your server and its share directory in Windows
1
format. For example, you would enter \\toltec\test, as shown in Figure 3-60, and use your server's
hostname instead of "toltec".
Figure
3-60.
Opening
a ashared
directory,
using
server's This
NetBIOS
name
in
Using Samba,
Second
Edition is
comprehensive
guide to
Sambathe
administration.
new edition
covers
UNC
all versions of Samba from 2.0 to 2.2, includingthe
selected
features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
This will work even if browsing services are not set up right, which is a common problem. You can also
work around a name-service problem by entering the server's IP Address (such as 172.16.1.1 in our
example) instead of the Samba server's hostname, as shown in Figure 3-61.
Figure 3-61. Opening a shared directory, using the server's IP address in the
UNC
If things still aren't right, go directly to Section 12.2 to troubleshoot what is wrong with the network.
If it works, congratulations! Try copying files to and from the server by dragging their icons to and from
the Samba server's test folder. You might be pleasantly surprised how seamlessly everything works.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Windows NT domain make it worthwhile to spend the extra effort to implement a domain.
Index
In addition to Reviews
the domain features of that we discussed in Chapter 1, having a domain makes it possible
Reader and
Reviews
to use logon scripts
roaming profiles (also called roving profiles). A logon script is a text file of
Errata
commands that are run during startup, and a profile is a collection of information regarding the desktop
Using
Samba, 2nd
Edition the contents of the Start menu, icons that appear on the desktop, and other
environment,
including
characteristics
about
the GUI
environment
that users are allowed to customize. A roaming profile can
ByDavid Collier-Brown, Robert
Eckstein
, Jay Ts
follow its owner from computer to computer, allowing her to have the same familiar interface appear
wherever she logs on.
Publisher: O'Reilly
Samba 2.2 has the ability to act as a primary domain controller, supporting domain logons from Windows
95/98/Me/NT/2000/XP computers and allowing Windows NT/2000/XP[1] systems to join the domain as
domain member servers. Samba can also join a domain as a member server, allowing the primary
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
domain controller to be a Windows NT/2000 system or another Samba server.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
Updated
for Windows
2000,inME,
and XP,
thereferring
book also
explores
[1] When
we include
Windows XP intool.
discussions
of Windows
NT domains
this book,
we are
to Windows
XP
Samba's
new role
a to
primary
domain
domain
member
server,
support XP
forlater
the inuse
Professional
andas
not
the Home
edition.controller
The reasonand
for this
is explained
in the
section its
on Windows
thisof
chapter.
Windows
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Samba 2.2 does not support LDAP and Kerberos authentication of Active Directory,
so it cannot act as a Windows 2000 Active Directory domain controller. However,
Samba can be added to an Active Directory domain as a member server, with the
Windows 2000 domain controllers running in either mixed or native mode. The
Windows 2000 server (even if it is running in native mode) supports the Samba
server by acting as a PDC emulator, using the Windows NT style of authentication
rather than the Kerberos style.
If you're adding a Samba server to a network that has already been set up, you won't have to decide
whether to use a workgroup or a domain; you will simply have to be compatible with what's already in
place. If you do have a choice, we suggest you evaluate both workgroup and domain computing carefully
before rolling out a big installation. You will have a lot of work to do if you later need to convert one to
the other. One last thought on this matter is that Microsoft is developing Windows in the direction of
increased use of domains and is intending that eventually Windows networks be composed solely of
Active Directory domains. If you implement a Windows NT domain now, you'll be in a better position to
transition to Active Directory later, after Samba has better support for it.
In this chapter, we cover various topics directly related to using Samba in a Windows NT domain,
including:
Configuring and using Samba as the primary domain controller
Setting up Windows 95/98/Me systems to log on to the domain
Implementing user-level security on Windows 95/98/Me
Adding Windows NT/2000/XP systems to the domain
Configuring logon scripts, roaming profiles, and system policies
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
You will need to use at least Samba 2.2 to ensure that PDC functionality for
Windows
NT/2000/XP clients is present. Prior to Samba 2.2, only limited user
Reader
Reviews
If you would like more information on how to set up domains, see the file SambaPDC-HOWTO.html in the docs/htmldocs directory of the Samba source distribution.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
Samba
from
2.0 tocontroller
2.2, including
selected
features
fromthat
an alpha
of 3.0,active,
as welland
as
Samba
mustofbe
the only
domain
for the
domain.
Make sure
a PDCversion
isn't already
the SWAT
configuration
tool. Updated
for Windows
2000,
and XP, the book
also explores
that
there graphical
are no backup
domain controllers.
Samba
2.2 is not
able ME,
to communicate
with backup
domain
Samba's new
role
as a primary
controller
domain
server, its
support
the in
use
controllers,
and
having
domain domain
controllers
in your and
domain
withmember
unsynchronized
data
wouldfor
result
a of
Windows
NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
very
dysfunctional
network.
shared files and printers from Unix clients.
Although Samba 2.2 cannot function as, or work with, a Windows NT BDC, it is
possible to set up another Samba server to act as a backup for a Samba PDC. For
further information, see the file Samba-B DC-HOWTO.html in the docs/htmldocs
directory of the Samba source distribution.
Configuring Samba to be a PDC is a matter of modifying the smb.conf file, creating some directories, and
restarting the server.
Table of Contents
Index
security = user
Reviews
Reader Reviews
; logon path tells Samba where to put Windows NT/2000/XP roaming profiles
Publisher: O'Reilly
ISBN: 0-596-00256-4
logon drive = H:
Using; Samba,
Second
is aspecify
comprehensive
guide to Samba
logon home
is Edition
used to
home directory
and administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
tool.
Updated
for Windows 2000, ME, and XP, the book also explores
; Windows
95/98/Me
roaming
profile
location
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
logon
home = \\%L\%u\.win_profile\%m
shared files and printers from Unix clients.
; instead of jay, use the names of all users in the Windows NT/2000/XP
; Administrators group who log on to the domain
domain admin group = root jay
; the below works on Red Hat Linux - other OSs might need a different command
add user script = /usr/sbin/useradd -d /dev/null -g 100 -s /bin/false -M %u
And after the [global] section, add these three new shares:
[netlogon]
path = /usr/local/samba/lib/netlogon
writable = no
browsable = no
[profiles]
; you might wish to use a different directory for your
; Windows NT/2000/XP roaming profiles
path = /home/samba-ntprof
browsable = no
Table of Contents
writableIndex
= yes
Reviews
create mask
Reader
= Reviews
0600
Errata
mask =
Usingdirectory
Samba, 2nd Edition
0700
Publisher: O'Reilly
[homes]
Pub Date: February 2003
ISBN:only
0-596-00256-4
read
= no
Pages: 556
browsable
= no
Slots: 1
guest ok = no
archive
= yes
Usingmap
Samba,
Second
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Now for the explanation. If you are comparing this example to the configuration file presented in Chapter
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
2, you will notice that the first three parameter settings are similar. We start out in the [global] section
Samba's new role as a primary domain controller and domain member server, its support for the use of
by setting the NetBIOS name of the Samba server. We are using the default, which is the DNS hostname,
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
but are being explicit because the NetBIOS name is used in UNCs that appear later in smb.conf. The next
shared files and printers from Unix clients.
two lines, setting the workgroup name and choosing to use encrypted passwords, are identical to our
smb.conf file from Chapter 2. However, things are now a little different: even though it still reads
"workgroup", we are actually setting the name of the domain. For a workgroup, using encrypted
passwords is optional; when using a domain, they are required.
The next four lines set up our Samba PDC to handle browsing services. The line domainmaster=yes
causes Samba to be the domain master browser, which handles browsing services for the domain across
multiple subnets if necessary. Although it looks very similar, localmaster=yes does not cause Samba
to be the master browser on the subnet, but merely tells it to participate in browser elections and allow
itself to win. (These two lines are yet more default settings that we include to be clear.) The next two
lines ensure that Samba wins the elections. Setting the preferredmaster parameter makes Samba force
an election when it starts up. The oslevel parameter is set higher than that of any other system, which
results in Samba winning that election. (At the time of this writing, an os level of 65 was sufficient to win
over all versions of Windowsbut make sure no other Samba server is set higher!) We make sure Samba
is both the domain and local master browser because Windows NT/2000 PDCs always reserve the domain
master browser role for themselves and because Windows clients require things to be that way to find the
primary domain controller. It is possible to allow another computer on the network to win the role of local
master browser, but having the same server act as both domain and local masters is simpler and more
efficient.
The next two lines in the [global] section set up Samba to handle the actual domain logons. We set
security=user so that Samba will require a username and password. This is actually the same as in the
workgroup setup we covered in Chapter 1 and Chapter 2 because it is the default. The only reason we're
including it explicitly is to avoid confusion: another valid setting is security=domain, but that is for
having another (Windows or Samba) domain controller handle the logons and should never be found in
thesmb.conf of a Samba PDC. The next line, domainlogons=yes, is what tells Samba we want this
server to handle domain logons.
Defining a logon path is necessary for supporting roaming profiles for Windows NT/2000/XP clients. The
UNC \\%L\profiles\%u refers to a share held on the Samba server where the profiles are kept. The
variables%L and %u are replaced by Samba with the name of the server and the username of the logged
on user, respectively. The section in smb.conf defining the [profiles] share contains the definition of
exactly where the profiles are kept on the server. We'll get back to this topic a bit later in this chapter.
Thelogonscript=logon.bat line specifies the name of an MS-DOS batch file that will be executed
when the client logs on to the domain. The path specified here is relative to the [netlogon] share that is
defined later in the smb.conf file.
The settings of logondrive and logonhome have a couple of purposes. Setting logondrive=H: allows
the home directory of the user to be connected to drive letter H on the client. The logonhome parameter
is set to the location
the home directory on the server, and again, %u is replaced at runtime by the
Table of of
Contents
logged on user's
username. The home directory is used to store roaming profiles for Windows 95/98/Me
Index
clients. These Reviews
parameters tie into the [homes] share that we are adding, as we will explain a bit later.
Reader Reviews
Settingtimeserver=yes causes Samba to advertise itself as a time service for the network. This is
Errata
optional.
Using Samba, 2nd Edition
By
David
Collier-Brown
, Robert
Eckstein, Jay
Ts as a short-term measure in Samba 2.2 to give Samba a list of
The
domain
admingroup
parameter
exists
users who have administrative privileges in the domain. The list should contain any Samba users who log
on from
Windows
Publisher:
O'Reilly NT/2000/XP systems and are members of the Administrators or Domain Admins
groups,
if
roaming
profiles are to work correctly.
Pub Date: February 2003
ISBN: 0-596-00256-4
The last parameter to add to the [global] section is adduserscript, and you will need it only if one or
Pages: 556
more of your clients is a Windows NT/2000/XP system. We will tell you more about this in Section 4.2
later inSlots:
this 1chapter.
The rest of the additions to smb.conf are the definitions for three shares. The [netlogon] share is
necessary for Samba to handle domain logons because Windows clients need to connect to it during the
logon
process and
will Edition
fail if the
share
does not exist.
Other
than that,
the only function
of [netlogon]
is
Using Samba,
Second
is a
comprehensive
guide
to Samba
administration.
This new
edition covers
to
a repository
for logon
scripts
andincluding
system-policy
files,
which we
shall
in detailof
later
this
all be
versions
of Samba
from 2.0
to 2.2,
selected
features
from
an cover
alpha version
3.0,inas
well as
chapter.
path toconfiguration
a directory ontool.
the Updated
Samba server
is given,
and ME,
because
the the
clients
only
read
logon
the SWATThe
graphical
for Windows
2000,
and XP,
book
also
explores
scripts
and
system-policy
files from
the controller
share, theand
writable
=no
definition
is used
make for
thethe
share
Samba's
new
role as a primary
domain
domain
member
server,
its to
support
use of
read-only.
Users do not
need to see the
so wesecurity
set browsable
=no to
make
the share
invisible.
Windows NT/2000/XP
authentication
andshare,
filesystem
on the host
Unix
system,
and accessing
shared files and printers from Unix clients.
The[profiles] share is needed for use with Windows NT/2000/XP roaming profiles. The path points to a
directory on the Samba server where the profiles are kept, and in this case, the clients must be able to
read and write the profile data. The createmask (read and write permitted for the owner only) and
directorymask (read, write, and search permitted for the owner only) are set up such that a user's
profile data can be read and written only by the user and not accessed or modified by anyone else.
The[homes] share is necessary for our definitions of logondrive and logonhome to work. Samba uses
the[homes] share to add the home directory of the user (found in /etc/passwd ) as a share. Instead of
appearing as "homes", the share will be accessible on the client through a folder having the same name
as the user's username. We will cover this topic in more detail in Chapter 9.
At this point, you might want to run testparm to check your smb.conf file.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Tablemust
of Contents
computer thatIndex
it "knows" as being part of the domain. Each Windows NT/2000/XP system in the domain
has a computer
account in the domain controllers' database, which on a Windows NT/2000 hosted
Reviews
domain is the Reader
SAM database.
Although Samba uses a different method (involving the smbpasswd file), it
Reviews
also
treats computer
#smbpasswd
-a root
Pub Date: February 2003
ISBN: 0-596-00256-4
to add the root user to Samba's password database. In this case, do not provide smbpasswd with the
556
same Pages:
password
as the actual root account on the server. Create a different password to be used solely
Slots: 1computer accounts. This will reduce the possibility of compromising the root password.
for creating
When the computer account is created, two things must happen on the Samba server. An entry is added
to the smbpasswd file, with a "username" that is the NetBIOS name of the computer with a dollar sign
($)
appended
it. This
part isishandled
by the smbpasswd
command,
and you do This
not need
to perform
Using
Samba, to
Second
Edition
a comprehensive
guide to Samba
administration.
new edition
covers
any
additional
action to
implement
it. including selected features from an alpha version of 3.0, as well as
all versions
of Samba
from
2.0 to 2.2,
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
[2] to give the computer account a user
With
Samba
is also
required
in the /etc/passwd
Samba's
new2.2,
rolean
asentry
a primary
domain
controller
and domain file
member
server, its support for the use of
ID
(UID) on
the Samba
server.
Windows
NT/2000/XP
authentication
and filesystem security on the host Unix system, and accessing
shared
files and printers from Unix clients.
[2]
The entry in /etc/passwd might not be required in future Samba versions.
This account will never be used to log in to the Unix system, so it should not be given a valid home
directory or login shell. To make this part work, you must set the adduserscript parameter in your
Samba configuration file, using a command that adds the entry in the proper manner. On our Red Hat
Linux system, we set adduserscript to:
/usr/sbin/useradd -d /dev/null -g 100 -s /bin/false -M %u
This command adds an entry in /etc/passwd similar to the following:
aztec$:x:505:100::/dev/null:/bin/false
Again, notice that the username ends in a dollar sign. The user account shown has a "home directory" of
/dev/null, a group ID (GID) of 100, and a "login shell" of /bin/false. The -M flag in our useradd command
prevents it from creating the home directory. Samba replaces the %u variable in the useradd command
with the NetBIOS name of the computer, including the trailing dollar sign. The basic idea here is to create
an entry with a valid username and UID. These are the only parts that Samba uses. It is important that
the UID be unique, not also used for other accountsespecially ones that are associated with Samba
users.
If you are using some other variety of Unix, you will need to replace our useradd command with a
command that performs the same function on your system. If a command such as useradd does not
come with your system, you can write a shell script yourself that performs the same function. In any
case, the command should add a password hash that does not correspond to any valid password. For
example, in the /etc/shadow file of our Linux server, we find the following two lines:
jay:%1%zQ7j7ok8$D/IubyRAY5ovM3bTrpUCn1:11566:0:99999:7:::
zapotec$:!!:11625:0:99999:7:::
The first line is for jay's user account. The second field is the password hashthe long string between
the first and second colons. The second line is for the computer account of zapotec, a domain member
server. Its "username" ends with a dollar sign ($), and the second field in this case has been set to "!!",
which is an arbitrary string not produced from any password. Therefore, there is no valid password for
this account on the Linux host. Just about any ASCII string can be used instead of "!!". For example, you
could use "DISABLED" instead.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
4.3.1 Windows
95/98/Me
Errata
To enable domain logons with Windows 95/98/Me, open the Control Panel and double-click the Network
By
David
Collier-Brown
, Robert
, JayNetworks,
Ts
icon.
Then
click Client
for Eckstein
Microsoft
and click the Properties button. At this point, you should
see a dialog box similar to Figure 4-1. Select the Logon to Windows Domain checkbox at the top of the
dialog
box, O'Reilly
and enter the name of the domain as you have defined it with the workgroup parameter in
Publisher:
the Pub
Samba
configuration
file. Then click OK, and reboot the machine when asked.
Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
IfWindows complains that you are already logged into the domain, you probably
have an active connection to a share in the workgroup (such as a mapped network
drive). Simply disconnect the resource temporarily by right-clicking its icon and
choosing the Disconnect pop-up menu item.
When Windows reboots, you should see the standard logon dialog with an addition: a field for a domain.
The domain name should already be filled in, so simply enter your password and click the OK button. At
this point, Windows should consult the primary domain controller (Samba) to see if the password is
correct. (You can check the log files if you want to see this in action.) If it worked, congratulations! You
have properly configured Samba to act as a domain controller for Windows 95/98/Me machines, and your
client is successfully connected.
security for shares that reside on Windows 95/98/Me systems.[3] To enable this functionality, open the
Control Panel, double-click the Network icon, and click the Access Control tab in the dialog box. The
window should now look like Figure 4-2.
[3]
If you want to follow our example in this section, and your network doesn't have any Windows systems offering
shares, see Chapter 5 for directions on how to create one. Make sure you understand how to set up shares before
continuing with the directions presented here!
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of Samba
from control
2.0 to 2.2,
including
fromof
anyour
alpha
version
well as
Click
the User-level
access
radio
button, selected
and typefeatures
in the name
domain
in of
the3.0,
textasarea.
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
Click the OK button. If you get the dialog box shown in Figure 4-3, it means that shares are already on
Samba's
new role as a primary domain controller and domain member server, its support for the use of
the system.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
In that case, you might want to cancel the operation and make a record of each of the computer's
shares, making it easier to re-create them, and then redo this part. (To get a list of shares, open an MSDOS prompt window and run the netview\\computer_name command.) Otherwise, you will get a
message asking you to reboot to put the change in configuration into effect.
After rebooting, you can create shares with user-level access control. To do this, right-click the folder you
wish to share, and select Sharing.... This will bring up the Shared Properties dialog box, shown in Figure
4-4.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Click
the Shared
Publisher:
O'ReillyAs: radio button, and give the share a name and comment. Then click the Add... button,
andPub
you
will
see the Add Users dialog box, shown in Figure 4-5.
Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
What has happened is that Windows has contacted the primary domain controller (in this case, Samba)
and requested a list of domain users and groups. You can now select a user or group and add it to one or
more of the three lists on the righthand side of the windowfor Read Only, Full Access, or Custom
Controlby clicking the buttons in the middle of the window. When you are done, click the OK button. If
you added any users or groups to the Custom Control list, you will be presented with the Change Access
Rights dialog box, shown in Figure 4-6, in which you can specify the rights you wish to allow. Then click
the OK button to close the dialog box.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
You are now returned to the Shared Properties dialog box, where you will see the Name: and Access
ISBN: 0-596-00256-4
Rights: columns filled in with the permissions that you just created. Click the OK button to finalize the
Pages: 556
process. Remember, you will have to perform these actions on any folders that you had previously
1
sharedSlots:
using
share-level security.
4.3.3
Windows NT 4.0
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
To
Windows
NT for domain
logfor
in to
the computer
as Administrator
or another
user in
theconfigure
SWAT graphical
configuration
tool.logons,
Updated
Windows
2000, ME,
and XP, the book
also explores
the
Administrators
group,
open
the
Control
Panel,
and
double-click
the
Network
icon.
If
it
isn't
already
Samba's new role as a primary domain controller and domain member server, its support for the use of
selected,
click on the Network
Identification
tab.
Windows NT/2000/XP
authentication
and filesystem
security on the host Unix system, and accessing
shared files and printers from Unix clients.
Click the Change... button, and you should see the dialog box shown in Figure 4-7. In this dialog box,
you can choose to have the Windows NT client become a member of the domain by clicking the checkbox
marked Domain: in the Member of box. Then type in the name of the domain to which you wish the client
to log on; it should be the same as the one you specified using the workgroup parameter in the Samba
configuration file. Click the checkbox marked Create a Computer Account in the Domain, and fill in "root"
for the text area labeled User Name:. In the Password: text area, fill in the root password you gave
smbpasswd for creating computer accounts.
If Windows complains that you are already logged in, you probably have an active
connection to a share in the workgroup (such as a mapped network drive).
Disconnect the resource temporarily by right-clicking its icon and choosing the
Disconnect pop-up menu item.
After you press the OK button, Windows should present you with a small dialog box welcoming you to the
domain. Click the Close button in the Network dialog box, and reboot the computer as requested. When
Table up
of Contents
the system comes
again, the machine will automatically present you with a logon screen similar to the
Index
one for Windows 95/98/Me clients, except that the domain text area has a drop-down menu so that you
to the domainReader
using Reviews
any Samba-enabled user account on the Samba server.
Errata
Be ,sure
toEckstein
select,Jay
theTs
correct
ByDavid Collier-Brown
Robert
After you
enter
the password, Windows NT should consult the primary domain controller (Samba) to see
ISBN:
0-596-00256-4
if the Pages:
password
is correct. Again, you can check the log files if you want to see this in action. If it worked,
556
you have successfully configured Samba to act as a domain controller for Windows NT machines.
Slots: 1
Click the radio button labeled "Domain:" and fill in the name of your domain in the text-entry area. Then
click the OK button. This will bring up the Domain Username and Password dialog box. Enter "root" for
the username. For the password, use the password that you gave to smbpasswd for the root account.
If Windows complains that you are already logged in, you probably have an active
connection to a share in the workgroup (such as a mapped network drive).
Disconnect the resource temporarily by right-clicking its icon and choosing the
Disconnect pop-up menu item.
After you press the OK button, Windows should present you with a small dialog box welcoming you to the
domain. When you click the OK button in this dialog box, you will be told that you need to reboot the
computer. Click
theofOK
button in the System Properties dialog box, and reboot the computer as
Table
Contents
requested. When
Indexthe system comes up again, the machine will automatically present you with a Log On
to
box similar to the one shown in Figure 4-9.
Windows dialog
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
authentication
and filesystem
security
on the host
Unix system,
andappear.
accessing
If
you do NT/2000/XP
not see the Log
on to: drop-down
menu, click
the Options
<< button
and it will
Select
shared
files and
printers
Unix computer,
clients.
your
domain,
rather
thanfrom
the local
from the menu.
Be sure to select the correct domain in the logon dialog box. Once it is selected, it
might take a moment for Windows to build the list of available domains.
Enter the username and password of any Samba-enabled user in the User name: and Password: fields,
and either press the Enter key or click the OK button. If it worked, your Windows session will start up
with no error dialogs.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Click the radio button labeled "Domain:", and fill in the name of your domain in the text-entry area. Then
shared files and printers from Unix clients.
click the OK button. This will bring up the Domain Username and Password dialog box. Enter "root" for
the username. For the password, use the password that you gave to smbpasswd for the root account.
If Windows complains that you are already logged in, you probably have an active
connection to a share in the workgroup (such as a mapped network drive).
Disconnect the resource temporarily by right-clicking its icon and choosing the
Disconnect pop-up menu item.
After you press the OK button, Windows should present you with a small dialog box welcoming you to the
domain. When you click the OK button in this dialog box, you will be told that you need to reboot the
computer to put the changes into effect. Click the OK buttons in the dialog boxes to close them, and
reboot the computer as requested. When the system comes up again, the machine will automatically
present you with a Log On to Windows dialog box similar to the one shown in Figure 4-11.
Table of Contents
Index
Reviews
Reader Reviews
Errata
If you get a dialog box at this point that tells you the domain controller cannot be found, the solution is to
change a registry setting as follows.
Publisher: O'Reilly
Open
Pubthe
Date:
Start
February
Menu
2003
and click the Run... menu item. In the text area in the dialog box that opens, type
in "regedit"
and click the OK button to start the Registry Editor. You will be editing the registry, so follow
ISBN: 0-596-00256-4
the rest
of the
Pages:
556 directions very carefully. Click the "+" button next to the HKEY_LOCAL_MACHINE folder,
and in the contents that open up, click the "+" button next to the SYSTEM folder. Continue in the same
Slots: 1
manner to open CurrentControlSet, then Services, then Netlogon. (You will have to scroll down many
times to find Netlogon in the list of services.) Then click the Parameters folder, and you will see items
appear in the right side of the window. Double-click "requiresignorseal", and a dialog box will open. In the
Value data: text area, change the "1" to a "0" (zero), and click the OK button, which modifies the registry
Using
Second
is a comprehensive
guide
to Samba
This
new edition covers
both inSamba,
memory
and onEdition
disk. Now
close the Registry
Editor
and logadministration.
off and back on
again.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT
graphical
tool. Updated
for click
Windows
2000, ME,
XP,and
the it
book
also explores
If you
do not
see theconfiguration
Log on to: drop-down
menu,
the Options
<< and
button
will appear.
Select
Samba's
newfrom
role as
primary
domain
controller
domain member server, its support for the use of
your
domain
theamenu,
rather
than
the localand
computer.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Be sure to select the correct domain in the logon dialog box. Once it is selected, it
might take a moment for Windows to build the list of available domains.
Enter the username and password of any Samba-enabled user in the User name: and Password: fields,
and either press the Enter key or click the OK button. If it worked, your Windows session will start up
with no error dialogs.
Table
for the user. Index
Reviews
In
a Unix environment,
the ability to run such a script might lead to a very complex initialization and deep
Reader Reviews
customization. However, the Windows environment is mainly oriented to the GUI, and the command-line
Errata
functions are more limited. Most commonly, the logon script is used to run a net command, such as net
Using Samba, 2nd Edition
use, to connect a network drive letter, like this:
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
This command will make our [test] share (from Chapter 2) show up as the T: drive in My Computer.
Pub Date: February 2003
This will happen automatically, and T: will be available to the user at the beginning of her session, instead
ISBN: 0-596-00256-4
of requiring her to run the net use command or connect the T: drive using the Map Network Drive
Pages: 556
function of Windows Explorer.
Slots: 1
Notice also that the extension of our logon script is .bat. Be careful about thisan extension of .cmd will
work for Windows NT/2000/XP clients, but will result in errors for Windows 95/98/Me clients, which do
not recognize .cmd as an extension for batch files.
Because the logon script will be executed on a Windows system, it must be in MS-DOS text-file format,
with the end of line composed of a carriage return followed by a linefeed. The Unix convention is a
newline, which is simply a linefeed character, so if you use a Unix text editor to create your logon script,
you must somehow make it use the appropriate characters. With vim (a clone of the vi editor that is
distributed
with
Red
Linux), the method is to create a new file and use the command:
Table
of Hat
Contents
Index
Reviews
:se ff=dos
Errata
the command:
Using Samba, 2nd Edition
^X
EnterCollier-Brown
f dos Enter
ByDavid
, Robert Eckstein, Jay Ts
where^X is a Control-X character and Enter is a press of the Enter key. Another method is to create a
Publisher: O'Reilly
Unix-format file in any text editor and then convert it to MS-DOS format using the unix2dos program:
Pub Date: February 2003
ISBN: 0-596-00256-4
$unix2dos
unix_file >logon.bat
Pages: 556
If yourSlots:
system
does not have unix2dos, don't worry. You can implement it yourself with the following
1
two-line Perl script:
#!/usr/bin/perl
Using
Samba,$ARGV[0];
Second Edition is a comprehensive guide to Samba administration. This new edition covers
open FILE,
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT
graphical
configuration
tool.} Updated for Windows 2000, ME, and XP, the book also explores
while
(<FILE>)
{ s/$/\r/;
print
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
andsystem
filesystem
security
the and
hostthen
Unixdrag
system,
and accessing
Or,
you can
use Notepad
on a Windows
to write
your on
script
the logon
script over to
shared
andSamba
printers
from Unix
clients.
a
folderfiles
on the
server.
In any
case, you can check the format of your script using the od
command, like this:
$od -c logon.bat
You should see output resembling this:
0000000
0000020
\r
\n
0000032
The important detail here is that at the end of each line is a \r\n, which is a carriage return followed by
a linefeed.
Our example logon script, containing a single net use command, was created and set up in a way that
allows it to be run successfully on any Windows client, regardless of which Windows version is installed
on the client and which user is authenticating or logging on to the domain. But what if we need to have
different users, computers, or Windows versions running different logon scripts?
One method is to use variables inside the logon script that cause commands to be conditionally executed.
For details on how to do this, you can consult a reference on batch-file programming for MS-DOS and
Windows NT command language. One such reference is Windows NT System Administration , published
by O'Reilly.
Windows batch-command language is very limited in functionality. Fortunately, Samba also supports a
means by which customization can be handled. The smb.conf file contains variables that can be used to
insert (at runtime) the name of the server (%L), the username of the person who is accessing the server's
resources (%u), or the computer name of the client system (%m). To give an example, if we set up the
path to the logon script as:
For more information on Samba configuration file variables, such as the %L,%u, and
Table
of Contentswe just used, see Chapter 6 and Appendix B.
%m variables
Index
Reviews
Reader Reviews
When modifying
and testing your logon script, don't just log off of your Windows session and log back on
Errata
to make
your
script
run. Instead, restart (reboot) your system before logging back on. Because Windows
Using
Samba,
2nd
Edition
often keeps the [netlogon] share open across logon sessions, the reboot ensures that Windows and
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Samba have completely released and reconnected the [netlogon] share, and the new version of the
logon script is being run while logging on.
Publisher: O'Reilly
More
logon scripts can be found in the O'Reilly book, Managing Windows NT
Pubinformation
Date: Februaryregarding
2003
Logons.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
All
Windows versions
Reviews can be configured individually for each user of the computer. Windows NT/2000/XP
supports
the
ability
to handle multiple user accounts, and Windows 95/98/Me can be configured for use
Reader Reviews
by multiple users, keeping the configuration settings for each user separate. Each user can configure the
Errata
computer's settings to her liking, and the system saves these settings as the user's profile, such that
Using Samba, 2nd Edition
upon logging on to the system, the user is presented with her familiar desktop.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Some of the settings, such as folder options or the image used for the desktop background, are held in
the Publisher:
registry.O'Reilly
Others, including the documents and folders appearing on the desktop and the contents of
the Pub
Start
menu,
are2003
stored as folders and files in the filesystem.
Date: February
ISBN: 0-596-00256-4
When the profile is stored on the local system, it is called a local profile. On Windows NT, local profiles are
556
storedPages:
in C:\winnt\profiles.
On Windows 2000/XP, they can be found in C:\Documents and Settings. On
Slots:
1
Windows
95/98/Me,
when configured for a single user (the default case), the local profile is scattered in
places such as the registry and directories such as C:\Windows\Desktop and C:\Windows\Start Menu .
When Windows 95/98/Me is configured for multiple users, the local profile of the preexisting user is
moved to a folder in C:\Windows\Profiles that has the same name as the user, and any users that are
Using Samba,added
subsequently
Second
toEdition
the computer
is a comprehensive
have their local
guide
profiles
to Samba
created
administration.
in that directory
Thisas
new
well.
edition
You can
covers
all versions
browse
through
of Samba
the local
from
profiles
2.0 toto
2.2,
seeincluding
their structureeach
selected features
has a
from
registry
an alpha
file (USER.DAT
version of 3.0,
for Windows
as well as
the SWAT and
95/98/Me
graphical
NTUS configuration
ER.DAT for Windows
tool. Updated
NT/2000/XP)
for Windows
and some
2000,
folders
ME, and
thatXP,
contain
the book
shortcuts
also explores
and
Samba's new role as a primary domain controller and domain member server, its support for the use of
documents.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
A
roaming
is a user
profile
is stored on a server and "follows" its owner around the network so
shared
filesprofile
and printers
from
Unixthat
clients.
that when the user logs on to the domain from another computer, his profile is downloaded from the
server and his familiar desktop appears on that computer as well.
Samba can support roaming profiles, and it is a fairly simple matter to configure it
for them. However, this is one feature that we recommend you do not use, at least
until you are sure you understand roaming profiles well and are very confident that
you can implement them with no harm incurred. If you want to (or are required to)
implement roaming profiles for your Windows clients, we suggest you first set up a
small domain with a Samba server and a few Windows clients exclusively for the
purposes of research and testing. Under no circumstances should you attempt to
implement roaming profiles in a careless or frivolous manner.
local profile during the user's logon session. When the user logs off the domain, the local profile is copied
back to the domain controller and stored as the new roaming profile. When the local profile is changed,
the server does not receive an update until the user logs off the domain or shuts down or reboots the
client. The client does not send an update to the server during the logon session, and a client does not
receive an update of a setting changed on another client during a logon session. When the user does log
off, changes in the configuration settings in the local profile are sent to the server, and the updates of the
roaming profile are available for the next logon session.
This simple behavior can lead to unexpected results when users are logged on to the domain on more
Contents
than one clientTable
at aoftime.
If a user makes a change to the configuration settings on one client and then
Index
logs off, the settings
can result in the roaming profile being modified accordingly. But the next client that
logs off mightReviews
cause those changes to be overwritten, and if so, the settings from the first client will be
lost. The behavior
ofReviews
different Windows versions varies with regard to this, and we've seen a wide variety
Reader
of behaviorsnot
Errataalways in alignment with Microsoft's documentation or even working the same way on
separate
occasions.
Sometimes Windows will refuse to overwrite a profile, perhaps giving an "access
Using
Samba,
2nd Edition
denied" error, and at other times it will seem to work while producing odd side effects. A common source
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
of confusion is what happens if a file is added to or deleted from the desktop, which is by default
configured to be part of the profile. A deleted file might later reappear, and it is even possible for a file to
Publisher: O'Reilly
irrecoverably
disappear without warning (on Windows 95/98). Or maybe a file that is added to the
Pub Date:
2003
desktop
on February
one client
never gets added to the roaming profile and fails to propagate to other clients. This
ISBN:
behavior
is 0-596-00256-4
somewhat improved on Windows 2000/XP, which attempts to merge items into the profile
that are
added
Pages:
556 on concurrently logged-on clients.
Slots: 1
One factor that comes into play is that Windows compares the timestamps of the local and roaming
profiles and can refuse to overwrite a roaming profile if it is newer than the local profile on the client, or
vice versa. For this reason, it is important to keep the clocks of the Windows clients and the Samba PDC
synchronized. We have already shown you how to do this, using the net time \\server/set/yes
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
command in the logon script.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
configuration
tool.correctly
Updatedconfigured,
for Windows
2000, ME,
and XP,that
thecan
book
also explores
EvenSWAT
whengraphical
the server
and clients are
a number
of things
happen
make
Samba's
new
role
as
a
primary
domain
controller
and
domain
member
server,
its
support
forthan
the use
things seem "broken." The most common occurrence is that some shortcuts on clients other
the of
one
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
that created the roaming profile will not work. These shortcuts can exist on the desktop or as items in the
shared
files and
from
clients.
Start menu.
Thisprinters
behavior
is aUnix
result
of applications or files that exist on one computer but not others.
Windows will display these shortcuts, but if they appear on the desktop, they will have a generic icon and
will bring up an error message if a user double-clicks them.
Because profiles can and usually do include the contents of the desktop and other
folders, it is possible for the roaming profile to grow to a huge size due to actions
of a user, such as creating new files on the desktop or copying files there. By
default, Internet Explorer keeps its disk cache in the Temporary Internet Files
folder in the profile and has been known to populate this directory with thousands
of files. This can result in a huge roaming profile that causes network congestion
and very large delays while users are logging on to the domain. (A fix for this can
be found in article Q185255 in the Microsoft Knowledge Base.)
One behavior we've seen a few times is that if, for some reason (e.g., a network error or
misconfiguration), the roaming profile is not available during the logon process, Windows will use the
local profile on the client instead. When this happens, the user might receive an unfamiliar profile, and all
the benefits of roaming profiles are lost for that logon session.
Table of Contents
Our
additions Index
to smb.conf that appeared earlier in this chapter included the two lines:
Reviews
logon
path =Reader
\\%L\profiles\%u\%m
Reviews
Errata
By
David
, Robert
Eckstein
Jay Ts
The
firstCollier-Brown
line specifies
where
the ,roaming
directories on Linux. This will make it simple to include the roaming profiles in backups of the home
directories. You can use another directory if you like.
Notice that in both logonpath and logonhome, the directory we specify ends in %m, which Samba
replaces with the NetBIOS name of the client. We are using the client's computer name to identify
indirectly which version of Windows it is running.
Initially, the directories you specify to hold the roaming profiles will be empty and will become populated
as clients log off for the first time. (Samba will even create the directories if they do not already exist.) At
first, the directories
Table ofwill
Contents
simply contain profiles that are identical to the clients' local profiles, and we
highly recommend
Index that you make a backup at this point before things get complicated. A listing of the
roaming profile
directory for user iman, after she has logged off from Windows 98 clients mixtec and
Reviews
pueblo and Windows
Me clients huastec and navajo, might look something like the following:
Reader Reviews
Errata
$ls -l /home/iman/.win_profile
Using Samba, 2nd Edition
By
David 4
Collier-Brown, Robert Eckstein, Jay Ts
total
drwx-----Publisher: O'Reilly
6 iman
iman
4096 Dec
8 18:09 huastec
iman
4096 Dec
7 03:47 mixtec
drwx-----9 iman
ISBN: 0-596-00256-4
Pages: 556
drwx------
11 iman
iman
4096 Dec
7 03:05 navajo
drwx------
11 iman
iman
4096 Dec
7 03:05 pueblo
Slots: 1
If things were left like this, the clients would not share their roaming profiles, so next we change from
Using
Samba, Second
Edition
is a comprehensive
administration.
using separate
directories
to having
symbolic linksguide
pointto
toSamba
common
directories: This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
#
mv SWAT
mixtec
graphical
Win98 configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
#
mv navajo
NT/2000/XP
WinMe
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
#rm huastec pueblo
#ln -s Win98 pueblo
#ln -s WinMe huastec
#chown iman:iman *
#ls -l /home/iman/.win_profile
total 6
lrwxrwxrwx
1 iman
iman
lrwxrwxrwx
1 iman
iman
lrwxrwxrwx
1 iman
iman
lrwxrwxrwx
1 iman
iman
drwx------
9 iman
iman
4096 Dec
7 03:47 Win98
drwx------
11 iman
iman
4096 Dec
7 03:05 WinMe
Now when iman logs on to the domain from either Windows 98 system, the client from which she is
logging on will get the profile stored in the Win98 directory (that started out as her local profile on
mixtec). This works likewise for the Windows Me clients.
To show a more complete example, here is a listing of a fully operational Windows 95/98/Me profiles
directory:
$ls -l /home/jay/.win_profile
total 12
lrwxrwxrwx
1 jay
jay
lrwxrwxrwx
1 jay
jay
1 jay
jay
jay
jay
jay
lrwxrwxrwx
Table of Contents
lrwxrwxrwx
Index
1 jay
Reviews
lrwxrwxrwx
Reader
1 jay
Reviews
Errata
lrwxrwxrwx
1 jay
Using Samba, 2nd Edition
lrwxrwxrwx
1 jay
jay
Publisher: O'Reilly
lrwxrwxrwx
1 jay
jay
jay
4096 Dec
8 18:09 Win95
Pages: 556
drwx-----Slots: 1
9 jay
jay
4096 Dec
7 03:47 Win98
drwx------
11 jay
jay
4096 Dec
7 03:05 WinMe
lrwxrwxrwx
1 jay Editionjay
5 guide
Nov 21
-> Win98This new edition covers
Using Samba, Second
is a comprehensive
to 22:48
Sambayaqui
administration.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
lrwxrwxrwx
1 jay
jay tool. Updated 9
16 22:14
zuni
the SWAT graphical
configuration
forNov
Windows
2000,
ME, ->
and/home/jay
XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Again, the computer name of each client exists in this directory as a symbolic link that points to the
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
directory containing the actual roaming profile. For example, maya, a client that runs Windows 98, has a
shared files and printers from Unix clients.
symbolic link named maya to the Win98 directory. A listing of Win98 shows:
$ls -l Win98
total 148
drwxr-xr-x
3 jay
jay
drwxr-xr-x
2 jay
jay
drwxr-xr-x
3 jay
jay
4096 Dec
drwxr-xr-x
3 jay
jay
drwxr-xr-x
2 jay
jay
drwxr-xr-x
2 jay
jay
4096 Dec
drwxr-xr-x
3 jay
jay
-rw-r--r--
1 jay
jay
114720 Dec
7 03:47 Desktop
7 03:47 Recent
7 03:46 USER.DAT
The contents of the Win95 and WinMe directories appear similar and contain roaming profiles that work
exactly as they should on their respective operating systems.
Notice in the previous listing that aztec and zuni are symbolic links to /home/jay. We've cautioned you
never to configure a roaming profile directory to be a user's home directory, but this is to handle
something different. The clients aztec and zuni are Windows XP systems, which handle logonhome
differently than other versions of Windows. We have set logonhome=\\%L\%u\.winprofile, and all
versions of Windows except for Windows XP strip off everything after \\%L\%u and correctly locate the
home directoryin this case, /home/jay. Windows XP uses the full UNC, so we simply add a symbolic link
to redirect it to the correct directory to get the net use H: /home command to work as it should. The
roaming profiles for Windows XP systems are not affected by this and are kept with the other roaming
profiles in the Windows NT/2000/XP family, as shown in this listing:
$ls -l /home/samba-ntprof/jay
total 16
lrwxrwxrwx
1 jay
Table of Contents
lrwxrwxrwx
Index
1 jay
Reviews
lrwxrwxrwx
1 jay
Reader
Reviews
Errata
lrwxrwxrwx
1 jay
Using Samba, 2nd Edition
jay
jay
jay
jay
lrwxrwxrwx
1 jay
jay
Publisher: O'Reilly
drwx-----13 jay
jay
4096 Dec
3 15:24 qero
jay
4096 Dec
1 20:31 Win2K
drwx-----ISBN: 0-596-00256-4
13 jay
Pages: 556
drwx-----Slots: 1
12 jay
jay
drwx------
13 jay
jay
lrwxrwxrwx
1 jay
jay
5 Nov 20 06:09 yavapai -> WinXP
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
lrwxrwxrwx
1 jay
jay
5 Nov 13 12:34 zapotec -> Win2K
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
lrwxrwxrwx
1 jay
jay
5 Nov 13 12:35 zuni -> WinXP
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
As you can see, we are using a similar method for the Windows NT/2000/XP roaming profiles. In the
listing,qero is not a symbolic link, but rather a directory that holds the roaming profile for qero, a
Windows 2000 client that has recently been added. We had not created a symbolic link called qero before
installing Windows 2000, so when jay logged off for the first time, Samba created a directory named qero
and copied the roaming profile received from the client to the new directory. Because this is a separate
directory from Win2K, which all other Windows 2000 clients are using to share their roaming profiles, the
roaming profile for qero works like a local profile, except that it is stored on the primary domain
controller.
This might seem like an odd thing to do, but it has some purpose. Sometimes you might wish to isolate a
client in this manner, especially while the operating system is being installed and initially configured.
Remember, if that client, with its default local profile, is logged off the domain, the local profile will be
written to the roaming profile directory. If the client were using the shared roaming profile directory, the
effect could be undesirable, to say the least. Using our method, the qero directory can later be renamed
to make it into an archival backup, or it can just be deleted. Then a new symlink named qero can be
created to point to the Win2K directory, and qero will share the roaming profile in Win2K with the other
Windows 2000 clients.
An alternative method is simply to create the symbolic links before the clients are added to the network.
After you become more comfortable with the way roaming profiles work, you might find this method to
be simpler and quicker.
Again, we urge you to be careful about letting different versions of Windows share the same roaming
profile. The method of configuring roaming profiles we've shown you here allows you to test a
configuration for a few clients at a time without affecting your whole network of clients. For example, we
could install a small number of Windows 2000 and Windows XP systems in the domain for testing
purposes and then create symlinks for them that point to a directory called Win2KXP to find out if sharing
roaming profiles between our Windows 2000 and Windows XP systems meets our expectations. The
Win2KXP directory could be created as an empty directory, in which case it would have a roaming profile
written to it by the first of the clients to log off. Or, Win2KXP could simply be a renamed roaming profile
directory that was created by one of the clients when it was added to the domain.
of Contents
Click
the User Table
Profiles
tab, and the dialog box will appear as shown in Figure 4-12.
Index
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Click
the
button
can clients.
customize their preferences and desktop settings." In the User profile
shared
files
and labeled
printers"Users
from Unix
settings box, you can check the options you prefer. When done, click the OK button and reboot as
requested. During this first reboot, Windows will copy the local profile data to C:\windows\profiles but will
not attempt to copy the roaming profile from the server. The next time the system is shut down, the local
profile will be copied to the server, and when Windows reboots, it will copy the roaming profile from the
server.
Figure 4-13. The Windows 2000 System Properties, User Profiles tab
Table of Contents
Index
Reviews
Reader Reviews
Errata
Notice in the figure that there are two entries for the username jay. The entry ZAPOTEC\jay refers to the
Publisher: O'Reilly
account on the local system, and METRAN\jay refers to the domain account. Recall that when a user logs
Date: February 2003
on, Pub
a drop-down
menu in the dialog box allows him to log on to a domain or log in to the local system.
ISBN:
0-596-00256-4
Whenjay logs
in to the local machine, only the local profile is used. When logged on to the domain, the
Pages: 556
configuration
shown will use the roaming profile. To switch a user's profile type for a domain logon
account,
Slots:
click
1 the account name to select it, then click the Change Type... button near the bottom of the
dialog box. The Change Profile Type dialog box will appear. Click the radio button for either roaming or
local profile, and then click the OK buttons for each dialog box.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba from
2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
4.5.5
Mandatory
Profiles
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
With a simple modification, a roaming profile can be made into a mandatory profile, which has the quality
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
of being unmodifiable by its owner. Mandatory profiles are used in some computing environments to
shared files and printers from Unix clients.
simplify administration. The theory is that if users cannot modify their profiles, less can go wrong, and it
is also possible to use the same standardized profile for all users.
In practice, some issues come up. Because the users can still modify the configuration settings in their
local profile during their logon session, confusion can result the next time they log on to the domain and
discover their changes have been "lost." If the user of a client reinstalls an application in a different place,
the shortcuts to the program on the desktop, in the Start menu, or in a Quick Launch bar cannot be
permanently deleted. They will reappear every time the user logs back on to the domain. Essentially, a
mandatory profile is a roaming profile that always fails to update to the server upon logging off!
Another complication is that different versions of Windows behave differently with mandatory profiles. If a
user who has a mandatory profile creates a new file on her desktop, the file might be missing the next
time the user logs off and on again or reboots. Some Windows versions preserve desktop files in the local
profile (even if the file does not exist in the mandatory profile), whereas others do not.
To change a roaming profile to a mandatory profile, all you have to do is rename the .dat file in the
roaming profile directory on the server to have a .man extension instead. For a Windows 95/98/Me
roaming profile, you would rename USER.DAT to USER.MAN, and for a Windows NT/2000/XP roaming
profile, you would rename NTUS ER.DAT to NTUS ER.MAN. Also, you might want to make the roamingprofile directory and its contents read-only, to make sure that a user can't change it by logging into his
Unix user account on the Samba host system.
If you want to have all your users share a mandatory profile, you can change the definitions of logon
path and logonhome in your smb.conf file to point to a shared mandatory profile on the server and
adjust your directory structure and symbolic links accordingly. For example, logonpath and logonhome
might be defined like this:
logon path = \\%L\profiles\%m
logon home = \\%L\%u\.win_profile\%m
Notice that we've removed the %u part of the path for logonpath, and we would also change the
directory structure on the server to do away with the separation of the profiles by username and have
just one profile for each Windows NT/2000/XP version.
We cannot use the same treatment for logonhome because it is also used to specify the home directory.
In this case, we would change the symbolic links in each user's .win_profile directory to point to a
common mandatory profile directory containing the mandatory profiles for each of Windows 95/98/Me.
Again, check the ownership and permissions on the files in the directory, and modify them if necessary to
make sure a user can't modify any files by logging into her Unix account on the Samba host system.
Table of Contents
Index
4.5.6
Logon
Script and Roaming-Profile Options
Reviews
Reader Reviews
Table 4-1 summarizes the options commonly used in association with Windows NT domain logon scripts
Errata
and roaming profiles.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Option
Parameters
Function
Default
Scope
Slots: 1
logon
script
None
Global
logon
string (UNC server and
\\%N\%U\profile Global
Location of roaming profile
path Samba,
Using
share
Second
name)
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
logon
Specifies the logon drive for a home
the SWAT graphical
configuration
the book also explores
string (drive
letter) tool. Updated for Windows 2000, ME, and XP,Z:
Global
drive
directory
Samba's new role as a primary domain
controller and domain member server, its support for the use of
Windows
authentication
filesystem
security
on thedirectories
host Unix system, and accessing
logon NT/2000/XP
string (UNC
server and and
Specifies
a location
for home
\\%N\%U
Global
shared
printers
home files and
share
name)from Unix clients.
for clients logging on to the domain
Table of Contents
NT/2000/XP clients only. For example:
Index
[global]
Reviews
Reader Reviews
Errata= I:
logon drive
You
should
always ,use
drive
letters
By
David
Collier-Brown
Robert
Eckstein
, Jaythat
Ts will not conflict with fixed drives on the client machine. The
default is Z:, which is a good choice because it is as far away from A:, C:, and D: as possible.
Publisher: O'Reilly
Pub Date: February 2003
4.5.6.4ISBN:
logon
home
0-596-00256-4
Pages: 556
This option specifies the location of a user's home directory for use by the MS-DOS net commands. For
Slots: 1
example, to specify a home directory as a share on a Samba server, use the following:
[global]
Usinglogon
Samba,
Second
Edition is a comprehensive guide to Samba administration. This new edition covers
home
= \\hydra\%U
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
Note
that this
graphical
worksconfiguration
nicely with the
tool.
[homes]
Updated
service,
for Windows
although2000,
you can
ME,specify
and XP,any
thedirectory
book also
you
explores
wish.
Samba's
new rolecan
as abe
primary
domain
andusing
domain
its support for the use of
Home
directories
mapped
with acontroller
logon script
the member
followingserver,
command:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
C:\>net
useand
i:printers
/home from Unix clients.
shared files
Table
of use
Contents
public use, such
as in a library, school, or Internet cafe.
Index
Reviews
A
system policy
is a collection of registry settings that is stored in a file on the PDC and is automatically
Reader Reviews
downloaded to the clients when users log on to the domain. The file containing the settings is created on
Errata
a Windows system using the System Policy Editor. Because the format of the registry is different between
Using Samba, 2nd Edition
Windows 95/98/Me and Windows NT/2000/XP, it is necessary to make sure that the file that is created is
By
Collier-Brown
, Robert
, Jaysimple
Ts
in David
the proper
format.
ThisEckstein
is a very
matter because when the System Policy Editor runs on
Windows 95/98/Me, it will create a file in the format for Windows 95/98/Me, and if it is run on Windows
NT/2000/XP,
Publisher: O'Reilly
it will use the format needed by those versions. After the policy file is created with the
System
Policy
Editor,
it is stored on the primary domain controller and is automatically downloaded by
Pub Date:
February
2003
the clients
during
the
logon process, and the policies are applied to the client system.
ISBN: 0-596-00256-4
Pages: 556
On Windows NT 4.0 Server, you can run the System Policy Editor by logging in to the system as
Slots: 1
Administrator
or another user in the Administrators group, opening the Start menu, and selecting
Programs, then Administrative Tools, then System Policy Editor. On Windows 2000 Advanced Server,
open the Start menu and click Run . . . . In the dialog box that comes up, type in
C:\winnt\poledit.exe, and click the OK button.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all you
If
versions
are using
of Samba
a Windows
from 2.0
version
to 2.2,
other
including
than NT
selected
Server features
or Windows
from2000
an alpha
Advanced
version
Server,
of 3.0,
you
as must
well as
the SWAT
install
the System
graphical
Policy
configuration
Editor, and
tool.
getting
Updated
a copy
for of
Windows
it can be
2000,
a little
ME,tricky.
and XP,
If you
the are
book
running
also explores
Windows
Samba's
NT
4.0 Workstation
new role asora Windows
primary domain
2000 Professional
controller and
anddomain
have a member
Windowsserver,
NT 4.0 its
Server
support
installation
for the use
CD- of
Windows
ROM,
youNT/2000/XP
can run the authentication
file \Clients\Svrtools\W
and filesystem
innt\S etup.bat
security from
on the
that
host
CDUnix
to install
system,
theand
Client-based
accessing
shared files
Network
Administration
and printersTools,
from Unix
which
clients.
includes poledit.exe. Then open the Start menu, click Run..., type
C:\winnt\system32\poledit.exe into the text area, and click the OK button.
If you are using Windows 95/98, insert a Windows 95 or Windows 98 distribution CD-ROM[4] into your
CD-ROM drive, then open the Control Panel and double-click the Add/Remove Programs button.
[4]
The version of the System Policy Editor distributed with Windows 98 is an update of the version shipped with
Windows 95. Use the version from the Windows 98 distribution if you can.
Click the Windows Setup tab, and then click the Have Disk... button. In the new dialog box that appears,
click the Browse... button, then select the CD-ROM drive from the Drives drop-down menu. Then:
If you are using a Windows 95 installation CD-ROM, double-click the admin, then apptools, then
poledit folder icons.
If you are using a Windows 98 installation CD-ROM, double-click the tools, then reskit, then
netadmin, then poledit folder icons.
You should see "grouppol.inf" appear in the File name: text area on the left of the dialog box. Click the
OK buttons in two dialog boxes, and you will be presented with a dialog box in which you should select
both the Group Policies and System Policy Editor checkboxes. Then click the Install button. Close the
remaining dialog box, and you can now run the System Policy Editor by opening the Start menu and
selecting Programs, then Accessories, then System Tools, then System Policy Editor. Or click the Run...
item in the Start Menu, and enter C:\Windows\Poledit.
When the System Policy Editor starts up, select New Policy from the File menu, and you will see a window
similar to that in Figure 4-14.
Table of Contents
Errata
The next step is to make a selection from the File menu to add policies for users, groups, and computers.
Index
For each item you add, you will be asked for the username, or name of the group or computer, and a
Reviews
new icon will appear in the window. Double-clicking one of the icons will bring up the Properties dialog
Reader Reviews
box, such as the one shown in Figure 4-15.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
The upper window in the dialog shows the registry settings that can be modified as part of the system
policy, and the lower window shows descriptive information or more settings pertaining to the one
selected in the upper window. Notice in the figure that there are three checkboxes and that they are all in
different states:
Checked
Meaning that the registry setting is enabled in the policy
White (unchecked)
Which clears the registry setting
Gray
Which causes the registry setting on the client to be unmodified
Basically, if all the items are left gray (the default), the system policy will have no effect. The registry of
the logged-on client will not be modified. However, if any of the items are either checked or unchecked
(white), the registry on the client will be modified to enable the setting or clear it.
In this section, we are giving you enough information on using the System Policy
Editor to get you startedor, should we say, enough rope with which to hang
yourself. Remember that a system policy, once put into action, will be modifying
the registries of all clients who log on to the domain. The usual warnings about
editing a Windows registry apply here with even greater importance. Consider how
difficult (or even impossible) it will be for you to restore the registries on all those
clients if anything happens to go wrong. As with roaming profiles, casual or
careless implementation of system policies can easily lead to domain-wide disaster .
Table of Contents
Index
Reviews
detail here. It would take a whole book, and yes, there happens to be an O'Reilly
Reader
bookReviews
on the subject, Windows System Policy Editor . Another definitive source of
Errata
documentation on Windows NT system policies and the System Policy Editor is the
Creating a good system policy file is a complex topic, which we cannot cover in
which
canEckstein
be found
ByDavid Collier-Brown
, Robert
, Jay at
Ts
http://www.microsoft.com/ntserver/techresources/management/prof_policies.asp.
Publisher: O'Reilly
Once
have
created
Pubyou
Date:
February
2003 a policy, click the OK button and use the Save As... item from the File menu to
save it.ISBN:
Use0-596-00256-4
the filename config.pol for a Windows 95/98 system policy and ntconfig.pol for a policy that
will be used on Windows NT/2000/XP clients. Finally, copy the .pol file to the directory used for the
Pages: 556
[netlogon] share on the Samba PDC. The config.pol and ntconfig.pol files must go in this
Slots: 1
directoryunlike roaming profiles and logon scripts, there is no way to specify the location of the system
policy files in smb.conf. If you want to have different system policies for different users or computers,
you must perform that part of the configuration within the System Policy Editor.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba
to 2.2,
including
selected
from
an network,
alpha version
of 3.0, as well as
If you from
have,2.0
or will
have,
any Windows
Mefeatures
clients on
your
be careful.
the SWAT graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
alsoodd
explores
Microsoft has stated that Windows Me does not support system policies. The
Samba's new role
as
a
primary
domain
controller
and
domain
member
server,
its
support
for
the
thing about this is that it will download the policy from a config.pol file on the PDC,use of
Windows NT/2000/XP
authentication
and filesystem
security
host
Unix
system,
and accessing
but there
is no guarantee
that the results
willon
bethe
what
was
intended.
Check
the
shared files andeffect
printers
from
Unix
clients.
of your system policy carefully on your Windows Me clients to make sure it is
working how you want.
When a user logs on to the domain, her Windows client will download the .pol file from the server, and
the settings in it (that is, the items either checked or cleared in the System Policy Editor) will override the
client's settings.
If things "should work" but don't, try shutting down the Windows client and restarting, rather than just
logging off and on again. Windows sometimes will hold the [netlogon] share open across logon sessions,
and this can prevent the client from getting the updated .pol file from the server.
Table to
of Contents
Windows NT/2000/XP
clients can have computer accounts on a Samba PDC. When a client accesses
Index
shares on the Reviews
Samba domain member server, Samba will pass off the authentication to the domain
controller rather
thanReviews
performing the task on the local system. If the PDC is a Windows server, any
Reader
number
of Windows
Errata BDCs might exist that can handle the authentication instead of the PDC.
Using Samba, 2nd Edition
The first step is to add the Samba server to the domain by creating a computer account for it on the
By
David Collier-Brown
, Robert Eckstein
, Jay do
Ts this using the smbpasswd command, as follows:
primary
domain controller.
You can
#smbpasswd
-j DOMAIN -r PDCNAME -Uadmin_acct%password
Publisher: O'Reilly
Pub Date: February 2003
In this command, DOMAIN is replaced by the name of the domain the Samba host is joining, PDCNAME is
ISBN: 0-596-00256-4
replaced by the computer name of the primary domain controller, admin_acct is replaced by the
Pages: 556
username of an administrative account on the domain controller (either Administratoror another user in
Slots: 1
the Administrators
groupon Windows NT/2000, and root on Samba), and password is replaced with the
password of that user. To give a more concrete example, on our domain that has a Windows NT 4 Server
primary domain controller or a Windows 2000 Active Directory domain controller named SINAGUA, the
command would be:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
#
smbpasswd
versions of-jSamba
METRAN
from
-r 2.0
SINAGUA
to 2.2,-UAdministrator%hup8ter
including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
and
if thenew
PDCrole
is aas
Samba
system,
we would
use the
Samba's
a primary
domain
controller
andcommand:
domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
#
smbpasswd
-j METRAN
toltec
-Uroot%jwun83jb
shared
files and
printers -r
from
Unix clients.
wherejwun83jb is the password for the root user that is contained in the smbpasswd file, as we
explained earlier in this chapter.
If you did it right, smbpasswd will respond with a message saying the domain has been joined. The
security identifier[5] returned to Samba from the PDC is kept in the file
/usr/local/samba/private/secrets.tdb. The information in secrets.tdb is security-sensitive, so make sure
to protect secrets.tdb in the same way you would treat Samba's password file.
[5]
This security identifier (SID) is part of an access token that allows the PDC to identify and authenticate the client.
The next step is to modify the smb.conf file. Assuming you are starting with a valid smb.conf file that
correctly configures Samba to function in a workgroup, such as the one we used in Chapter 2, it is simply
a matter of adding the following three lines to the [global] section:
workgroup = METRAN
security = domain
password server = *
The first line establishes the name of the domain (even though it says "workgroup"). Instead of METRAN,
use the name of the domain you are joining. Setting security to "domain" causes Samba to hand off
authentication to a domain controller, and the passwordserver=* line tells Samba to find the domain
controller for authentication (which could be the primary domain controller or a backup domain
controller) by querying the WINS server or using broadcast packets if a WINS server is not available.
At this point, it would be prudent to run testparm to check that your smb.conf is free of errors. Then
restart the Samba daemons.
If the PDC is a Windows NT system, you can use Server Manager to check that the Samba server has
been added successfully. Open the Start menu, then select Programs, then Administrative Tools
(Common), and then Server Manager. Server Manager starts up with a window that looks like Figure 416.
Table of Contents
Index
Reviews
Reader Reviews
Errata
As
you can see, we've added both toltec and mixtec to a domain for which the Windows NT 4.0 Server
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
system,sinagua, is the primary domain controller.
O'Reilly
YouPublisher:
can check
your setup on Windows 2000 Advanced Server by opening the Start menu and selecting
Pub Date:then
February
2003
Programs,
Administrative
Tools, then Active Directory Users and Computers. The window that opens
up willISBN:
look 0-596-00256-4
like Figure 4-17.
Pages: 556
Slots: 1 4-17. The Windows 2000 Active Directory Users and Computers
Figure
window
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Click Computers in the left side of the window with the Tree tab. You should see your Samba system
listed in the right pane of the window.
Table of Contents
Index
Reviews
Table
Reader Reviews
Errata
Using Option
Samba, 2nd Edition
Parameters
Function
Default
Scope
domain logons
boolean
No
Global
Auto
Global
Publisher: O'Reilly
Pub Date:
February boolean
2003
domain
master
ISBN: 0-596-00256-4
Pages: 556
add user
script
Slots: 1
string
(command)
None
Global
delete user
script
string
(command)
None
Global
domain
adminSecond
Using
Samba,
string
Edition
(list of
is a comprehensive guide to Samba administration. This new edition covers
Users that are in the Domain Admins group
None
Global
group
all
versions of Samba
users)
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
domain guest
string
(list of domain controller and domain member server, its support for the use of
Samba's new role as
a primary
Users that are in the Domain Guests group
None
Global
group
users)
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
List of domain controllers used for
password
string (list of
authentication when Samba is running as a
None
Global
server
computers)
domain member server
machine
password
timeout
numeric
(seconds)
604,800 (1
week )
Global
Here are detailed explanations of each Windows NT domain option listed in Table 4-2.
Table
of computer's
Contents
a
user
who
has
administrative
rights
on the domain controller. Samba authenticates this user and then
Index
runs the adduserscript with root permissions.
Reviews
Reviews
When Samba Reader
is configured
as a domain member server, the adduserscript can be assigned to a
Errata
command to add a user to the system. This allows Windows clients to add users that can access shares
Using Samba, 2nd Edition
on the Samba system without requiring an administrator to create the account manually on the Samba
By
David Collier-Brown, Robert Eckstein, Jay Ts
host.
Publisher: O'Reilly
4.8.1.3
delete
user
script
Pub Date:
February
2003
ISBN: 0-596-00256-4
TherePages:
are times
556 when users are automatically deleted from the domain, and the deleteuserscript can
be assigned
Slots: 1 to a command that removes a user from the Samba host as a Windows server would do.
However, you might not want this to happen, because the Unix user might need the account for reasons
other than use with Samba. Therefore, we recommend that you be very careful about using this option.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
4.8.1.4
domain
admin
group
all versions
of Samba
from
2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
newofrole
as a primary
domain
controller
domain
its support
use of
In
a domain
Windows
systems,
it is possible
forand
a server
to member
get a list server,
of the members
of for
thethe
Domain
Windowsgroup
NT/2000/XP
authentication
andSamba
filesystem
security
thethe
host
Unix to
system,
accessing
Admins
from a domain
controller.
2.2 does
noton
have
ability
handleand
this,
and the
shared admin
domain
files and
group
printers
parameter
from Unix
existsclients.
as a manual means of informing Samba who is in the group. The
list should contain root (necessary for adding computer accounts) and any users on Windows NT/2000/XP
clients in the domain who are in the Domain Admins group. These users must be recognized by the
primary controller in order for them to perform some administrative duties such as adding users to the
domain.
If you would like more information on how Windows NT uses domain usernames
and groups, we recommend Eric Pearce'sWindows NT in a Nutshell, published by
O'Reilly.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Windows! In this chapter, we will show you the "other side"how to access SMB shares from your
Index
favorite Unix system.
Reviews
Reader
You can access
SMB Reviews
resources from Unix in three ways, depending on your version of Unix. A program
Errata
included with the Samba distribution called smbclient can be used to connect with a share on the network
Using
Samba, 2nd
Edition
in
a manner
similar
to using ftp when transferring files to or from an FTP site.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
If your system is running Linux, you can use the smbfs filesystem to mount SMB shares right onto your
Linux filesystem, just as you would mount a disk partition or NFS filesystem. The SMB shares can then be
Publisher: O'Reilly
accessed
and manipulated by all programs running on the Linux system: command shells, desktop GUI
Pub Date: and
February
2003
interfaces,
application
software.
ISBN: 0-596-00256-4
On some
BSD-based
systems, including Mac OS X, a pair of utilities named smbutilandmount_smbfs
Pages:
556
can beSlots:
used1 to query SMB servers and mount shares.
For other Unix variants, smbsh can be run to enable common shell commands such as cd,ls,mv, wc, and
grep to access and manipulate files and directories on SMB shares. This effectively extends the reach of
the Unix shell and utilities beyond the Unix filesystem and into the SMB network.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
Samba
2.0shares
to 2.2,offered
including
featuressystems
from anor
alpha
version
of 3.0,
well as
All versions
the Unix of
clients
canfrom
access
by selected
either Windows
Samba
servers.
Weas
have
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
already shown you how to set up a share on a Samba server and could use that as an example to work
Samba's
role as
a primary
and
domain
member
its support
for the
use of
with.
But new
it's much
more
fun to domain
use the controller
Unix clients
with
shares
served server,
by Windows
systems.
So before
Windows
NT/2000/XP
authentication
and filesystem
security
on detour
the host
Unix
system,
andto
accessing
we
start covering
the Unix
clients in detail,
we will take
a quick
and
show
you how
set up file
shared on
filesboth
andWindows
printers from
Unix clients.
shares
95/98/Me
and Windows NT/2000/XP systems.
TableaofSamba
Contents
Index
Errata
To
type of access control for your system, open the Control Panel, double-click the Network
configure the
Reviews
icon,
then
click
the
Access Control tab. You should see the dialog box shown in Figure 5-1.
Reader Reviews
Figure 5-1. The Access Control tab of the Windows 98 Network Control Panel
window
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Click the "Share-level access control" or "User-level access control" radio button, depending on which you
want to use. When using user-level access control, you will also need to fill in the name of your
workgroup or Windows NT domain. Reboot as requested.
To share a folder, right-click the folder's icon and select Sharing . . . . This will open the Sharing tab of
the folder's Properties dialog box. Click the "Shared As:" radio button, and fill in a name for the share
(which defaults to the folder's name) and a description, which will be visible to client users. If you don't
want the share to be visible in the Network Neighborhood view of other Windows clients, pick a name for
the share that ends in a dollar sign ($).
Figure 5-2 shows what the Sharing tab of the folder's Properties dialog box will look like when using
share-level security. The security settings are very simple. You can select a radio button for read-only
access or full (read/write) access, or have the user's permissions (either read-only or read/write) depend
on which password they use. In accordance with which you select, you will be asked to assign either or
both of the read-only and full-access passwords for the share.
Figure 5-2. The Sharing tab of the folder's Properties dialog, with share-level
security
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
If your system is configured with user-level security, the Sharing tab of the folder's Properties dialog box
Pages: 556
will look like Figure 5-3. As you can see, we've created a share named "DATA", and used the Add . . .
Slots: 1
button to create permissions that allow read-only access for all domain users and read/write (full access)
forjay.
Figure 5-3. The Sharing tab of the folder Properties dialog, with user-level
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, includingsecurity
selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
When you are done specifying your settings for the share, click on the OK button, and the share will
become available to users on network clients. Unless you chose a share name ending in a dollar sign, you
can see it in the Network Neighborhood or My Network Places of Windows clients on the network. You can
also now use the Unix clients described in this chapter to connect to the share.
of Contents
Index
Reviews
Figure 5-4.
The Sharing tab of the folder's Properties dialog on Windows
Reader Reviews
2000
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Share name: will default to the name of the folder, and you can change it if you want. One reason you
might want to use a different name for the share is to make the share not appear in browse lists (as
displayed by the Network Neighborhood, for example). This can be done by using a share name ending in
a dollar sign ($). You can also add a description of the share in the Comment: text area. The description
will appear to users of network clients and can help them understand the contents of the share.
By clicking the Permissions button, you can set permissions for the share on a user-by-user basis. This is
equivalent to the user-level security of Windows 95/98/Me file sharing. On Windows NT/2000/XP,
Microsoft recommends that share permissions be set to allow full access by everyone, with the
permissions controlled on a file-by-file basis using filesystem access control lists (ACLs). The actual
permissions given to network clients are a combination of the share permissions and file access
permissions. To edit the ACL for the folder, click the Security tab. For more information on ACLs, see
Section 8.3 in Chapter 8.
If you want, you can limit the number of users who can concurrently connect to the share using the "User
limit:" radio button. The New Share button allows you to create multiple file shares for the same folder,
each having its own name, comment, user limit, and other parameters.
When you are done, click the OK button, and the folder will be accessible from clients on the network.
5.3 smbclient
The Samba Team supplies smbclient as a basic part of the Samba suite. At first, it might seem to be a
primitive interface to the SMB network, but smbclient is actually a versatile tool. It can be used for
browsing shares on servers, testing configurations, debugging, accessing shared printers, backing up
shared data, and
Tableautomating
of Contents administrative tasks in shell scripts. And unlike smbfs and smbsh,smbclient
works on all Unix
Reviews
In
this chapterReader
we'll Reviews
focus mostly on running smbclient as an interactive shell, using its ftp-like
commands to access shared directories on the network. Using smbclient to access printers and perform
Errata
backups will be covered in Chapter 10.
Using Samba, 2nd Edition
ByDavid
Collier-Brown
, Robert
Eckstein, Jay
A
complete
reference
to smbclient
isTs
found in Appendix C.
Publisher: O'Reilly
Pub Date:
February
2003
5.3.1
Listing
Services
ISBN: 0-596-00256-4
The-L Pages:
option556
can
be used with smbclient to list the resources on a single computer. Assuming the Samba
1
server Slots:
is configured
to take the role of the master browser, we can obtain a list of the computers in the
domain or workgroup like this:
$smbclient -L toltec
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
added
interface
ip=172.16.1.1
bcast=172.16.1.255
nmask=255.255.255.0
all versions
of Samba
from 2.0 to 2.2,
including selected features
from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Password:
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Domain=[METRAN]
OS=[Unix]
Server=[Samba
2.2.5]
shared files and printers
from Unix
clients.
Sharename
Type
Comment
---------
----
-------
test
Disk
IPC$
IPC
ADMIN$
Disk
Server
Comment
---------
-------
MAYA
Windows 98
MIXTEC
Samba 2.2.5
TOLTEC
Samba 2.2.5
ZAPOTEC
Workgroup
Master
---------
-------
METRAN
TOLTEC
In the column labeled "Server", maya,mixtec, and zapotec are shown along with toltec, the Samba
server. The services on toltec are listed under "Sharename". The IPC$ and ADMIN$ shares are standard
Windows services that are used for network communication and administrative purposes, and test is the
directory we added as a share in Chapter 2.
Now that we know
Table of
the
Contents
names of computers in the domain, we can list services on any of those
computers. For
example, here is how we would list the services offered by maya, a Windows 98
Index
workstation: Reviews
Reader Reviews
Errata
$smbclient -L maya
Password:
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Sharename
Type
Comment
---------
----
-------
UsingPRINTER$
Samba, Second Disk
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical configuration
tool.932C
Updated
for Windows 2000, ME, and XP, the book also explores
HP
Printer
HP
on Maya
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP Disk
authentication
filesystem security on the host Unix system, and accessing
D
D: and
on Maya
shared files and printers from Unix clients.
E
Disk
ADMIN$
Disk
IPC$
IPC
E: on Maya
Server
Comment
---------
-------
Workgroup
Master
---------
-------
A shared printer is attached to maya, so we see the PRINTER$ administrative service, along with the HP
share for the printer itself. Also on maya are the D and E shares, which allow access across the network to
maya's D: and E: drives. It is normal for the Server and Workgroup sections to be empty when listing
services on a Windows client.
in a domain environment or if it is contacting a Samba server that is set up with user-level security. In a
workgroup environment, it will at least need a password to use when connecting with a passwordprotected resource.
By default, smbclient uses the username of the user who runs it and then prompts for a password. If you
are using smbclient a lot, you might tire of entering your password every time.
smbclient supports some alternate methods of entering a username and password. The password can be
entered on the command line, like this:
Table of Contents
$
jayspassword
smbclient //maya/e
Index
Reviews
Errata
Or both the username and password can be supplied by using the -U option, including the username and
Reader Reviews
password separated by a percent (%) character:
Using
Samba, 2nd
Edition
$smbclient
//maya/e
-U kelly%kellyspassword
This method is useful if you are logged in to the system under an account that is not Samba-enabled or
youPublisher:
are testing
your configuration to see how it treats another user. With either method, you can avoid
O'Reilly
having to enter the username and/or password each time you run smbclient by creating an alias for the
Pub Date: February 2003
command or creating a shell function or shell script. For example, with the bash shell, it is possible to
ISBN: 0-596-00256-4
define a function like this:
Pages: 556
smbcl(Slots:
) 1
{
$* -U Edition
jay%jayspassword
Usingsmbclient
Samba, Second
is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
}
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Adding
the
definition to
the shell's startup
script (which
wouldonbe
~/.bash_profile
for bash)
would result
Windows
NT/2000/XP
authentication
and filesystem
security
the
host Unix system,
and accessing
in
the
definition
affecting
all
subsequent
shell
invocations.
shared files and printers from Unix clients.
Another method that can be used to supply both the username and password is to set the USER and
PASSWD environment variables. Either set the USER environment variable using the
username%password format, or set the USER environment variable to the username, and set PASSWD to
the user's password.
It is also possible to create a credentials file containing the username on the first line and the password
on the second line, like this:
username = jay
password = jayspassword
Then,smbclient is run using the -A option to specify the name of the file:
$smbclient //maya/e -A ~/.smbpw
Of the methods we described in this section, the only one that is really secure is
the default method of allowing smbclient to prompt for the password and typing in
the password without echoing.
If security is a concern, you definitely should avoid providing your password on the
command line because it is very easy for "shoulder surfers" to obtain, as well as
anyone who looks through your shell's command history.
Table
of Contents
If you
keep your Samba password in a credentials file, shell startup file, or shell
Index
script, make sure the file's permissions prohibit other users from reading or writing
Reviews
it. (Use an octal permissions mode of 0600.) Security experts never keep
Reader
Reviewsin files owned by nonroot users or accessible by anyone other than the
passwords
Errata
superuser. As part of their security policy, some organizations do not permit
to be stored in files, so you might want to check first before using this
method.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The authentication method that uses the USER and PASSWD environment variables
isn't any more secure. Environment variables are usually set either on the
Pub Date: February
2003
command
line or in one or more of the shell's startup files, so this method suffers
ISBN: 0-596-00256-4
from the same weaknesses we've just discussed. In addition, any program run by
Pages: 556 the user has access to the shell's environment variables, making a Trojan horse
attack on the PASSWD variable really easy!
Slots: 1
Publisher: O'Reilly
dir
du
lcd
cd
pwd
get
mget
put
mput
rename
more
mask
del
open
rm
mkdir
md
rmdir
rd
prompt
recurse
translate
lowercase
printmode
queue
cancel
quit
exit
newer
archive
tar
blocksize
tarmode
setmode
help
history
!
Some commands in the previous list are synonyms for other commands. For example, the ? command is
a synonym for help. You can give this command the name of another command as an argument to get a
concise reminder of what the command does and how to use it:
smb: \> ? ls
HELP
ls:
Table of Contents
Index
Reviews
Reader Reviews
The term <mask>
refers to a file-matching pattern as commonly found in Unix shells and utilities. For
Errata
example:
Using Samba, 2nd Edition
smb:
\>Collier-Brown
ls *doc ,Robert Eckstein,Jay Ts
ByDavid
ms-ProfPol-wp.doc
Publisher: O'Reilly
Pub Date: February 2003
smbclient.doc
131
33969
7759
ISBN: 0-596-00256-4
Pages: 556
smbmount.doc
Slots: 1
2 jay
jay
drwxrwxr-x
2 jay
jay
-rw-rw-r--
1 jay
jay
drwxrwxr-x
7 jay
jay
lists the contents of /u/snd. By using smbclient's commands to operate on the remote systemand shellescaped commands to operate on the local systemit is possible to manipulate data on both systems
without having to exit smbclient or open another shell window.
File transfer is performed using the get and put commands. The get command transfers a single file from
the remote to the local system, and the put command copies a file from the local to the remote system.
For example, the following command copies the file readme.txt to the SMB share:
smb: \trans\> put readme.txt
Table of Contents
putting
fileIndex
readme.txt as \trans\readme.txt (127.9 kb/s) (average 10.7 kb/s)
Reviews
Reader Reviews
Unlikeftp,smbclient does not have ascii and binary commands to set the type of
Errata
file
Using Samba, 2nd the
Edition
that is being transferred. Before transferring a text file from a Unix system
to
a
Windows
or Macintosh system, you might want to use the GNU unix2dos
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
command to reformat newlines in the file to work with the carriage return linefeed
(CRLF) standard:
Publisher: O'Reilly
text_file >text_file.txt
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
and then transfer the CRLF-formatted version. After transferring a text file from a
Windows or Macintosh system to Unix, you can use the GNU dos2unix command to
perform the inverse operation:
$dos2unix text_file.txt >text_file
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
To transfer more than one file with a single command, you can use the mget and mput commands, which
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
accept a list of filenames in the command line. The list can be provided by typing in the filenames on the
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
command line separated by spaces, or the group of files can be specified with a pattern as one would use
Samba's new role as a primary domain controller and domain member server, its support for the use of
in Unix shell commands. The command:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and mget
printers
from Unix clients.
smb: \trans\>
plain/*
copies all the files in the directory plain on the SMB share to the current directory on the local system. By
default,smbclient prompts for each file, asking if you want to copy it:
smb: \trans\> mget plain/*
Get file tomm.wav? n
Get file toml.wav? n
Get file tomh.wav? n
Get file snare.wav? n
Get file rim.wav? n
Get file handclap.wav? n
Get file bassdrum.wav? n
If you are sure you want to copy all the files, you can turn off prompting with the prompt command, like
this:
smb: \trans\> prompt
prompting is now off
By default, if you specify the name of a directory, smbclient will not copy the contents of the directory. To
transfer the entire contents of directories listed in the mput or mget command, you must first use the
recurse command:
Table of Contents
getting
fileIndex
toml.wav of size 57220 as toml.wav (2660.9 kb/s) (average 2167.6 kb/s)
Reviews
getting
fileReader
tomh.wav
of size 55936 as tomh.wav (2601.2 kb/s) (average 2220.8 kb/s)
Reviews
Errata
getting
file
of size 22132 as snare.wav (1200.7 kb/s) (average 2123.7 kb/s)
Using Samba,
2ndsnare.wav
Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
getting file rim.wav of size 8314 as rim.wav (1623.8 kb/s) (average 2110.8 kb/s)
Publisher:
O'Reilly
getting
file
handclap.wav of size 14180 as handclap.wav (1978.2 kb/s) (average 2106.2
Pub Date: February 2003
getting
file bassdrum.wav of size 6950 as bassdrum.wav (2262.3 kb/s) (average 2108.5
Slots: 1
kb/s)
Directory recursion applies to all commands, so if an ls command is used while directory recursion is on,
Using
Second Edition
is listed.
a comprehensive
guide to
Samba off
administration.
new edition
covers
all filesSamba,
in the directory
tree are
To turn directory
recursion
again, simplyThis
re-enter
the
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as
well
as
command. At the same time, you might also wish to toggle prompting back to its initial state:
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role
as a primary domain controller and domain member server, its support for the use of
smb:
\trans\>
recurse
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files recursion
and printersisfrom
directory
nowUnix
off clients.
smb: \trans\> prompt
prompting is now on
There are other smbclient commands that you might find useful. The mkdir command can be used to
create a directory; rmdir removes a directory; rm deletes a file; and rename changes a file's name. These
behave very similarly to their Unix shell counterparts. Appendix C contains a complete reference to
smbclient and its command set.
To exit smbclient, use the exit or quit command:
smb: \trans\> quit
smbls(
{
share=`echo $1 | cut -d '/' -f '1-4'`
dir=`echo $1 | cut -d '/' -f '5-'`
smbclient $share -c "cd $dir; ls" -A ~/.smbpw | \
Table of Contents
Index
Reviews
Reader Reviews
Errata
grep "^
After
defining
this
function, we can use smbls like this:
Using Samba,
2nd
Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
$smbls //maya/e
Publisher: O'Reilly
CD-images
lectures
ISBN: 0-596-00256-4
Pages: 556
ms-ProfPol-wp.doc
Slots: 1
profile-map
readme.txt
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
RECYCLED
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role as a primary domain controller and domain member server, its support for the use of
smbclient.doc
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and printers from Unix clients.
smbmount.doc
smbsh.txt
trans
$smbls //maya/e/lectures
.
..
lecture1.mp3
lecture2.mp3
lecture3.mp3
lecture4.mp3
lecture5.mp3
lecture6.mp3
lecture7.mp3
lecture8.mp3
lecture9.mp3
Another use for smbclient in scripts is performing administrative tasks. Suppose a group of users on
Windows clients are sharing a set of files as part of a project on which they are working. Instead of
expecting them to coordinate making daily backups, we could write a script that copies the share to the
Samba server and run the script nightly as a cron job. The directory on the Samba server could be
shared as well, allowing any of the users to retrieve a backup file on their own, without having to bother
an administrator.
Table of Contents
Reviews
smbclient on aReader
Unix Reviews
server to run network backups can result in a more centralized and easily managed
solution
for providing
data integrity because both SMB shares and NFS filesystems can be backed up on
Errata
the
same
system.
Using Samba, 2nd Edition
By
David
, Robert
, Jay
Ts
You
canCollier-Brown
use smbclient
to Eckstein
perform
backups
#smbclient
//maya/e -A samba-domain-pw -Tc >maya-e.tar
Pub Date: February 2003
ISBN: 0-596-00256-4
This will create a tar archive of the \\maya\e share in the file maya-e.tar. By using the -D option, it is
Pages: 556
possible
to back up a directory in the share, rather than the whole share:
Slots: 1
An alternative to extracting the tar archive directly to the SMB share is to use the Unix system's tar command to
extract it to a directory on the Unix server, then copy the desired file(s) to a shared directory. This allows a greater
amount of control over the restoration process, as when correcting for an accidental file deletion or reverting a set of
files to a previous condition.
The other options can be appended to the option string and are explained in the section on smbclient in
Appendix C. They allow you to create incremental backups, specify which files to include or exclude from
the backup, and specify a few other miscellaneous settings. For example, suppose we wish to create an
incremental backup of a share and reset the archive bit on the files to set things up for the next
incremental backup. Instead of using the interactive commands:
smb: \> tarmode inc reset quiet
Table
of Contents
have only a few
Windows
systems sharing a small amount of data, you might create a script containing
Reviews
regular backups of the Unix system. If you have huge SMB shares on your network, you
might prefer to
writeReviews
the backup directly to a tape drive. You can do this with smbclient just as you would
Reader
with a Unix tarErrata
command:
After you have become more familiar with smbclient and have an automated backup system in place, you
Publisher:
O'Reilly
might
find that
using Samba has dramatically decreased your anxiety regarding the integrity of your
network's
The2003
authors of this book are experienced Unix system administrators, and we highly
Pub Date:data.
February
recommend
having a backup strategy that has been carefully planned, implemented, and most
ISBN: 0-596-00256-4
importantly,
tested and known to work as it is supposed to .
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
5.4 smbfs
On Linux, the smbfs filesystem can be used to mount SMB shares onto the Linux filesystem in a manner
similar to mounting disk partitions on NFS filesystems. The result is so transparent that users on the
Linux system might never be aware that they are accessing files through a Windows or Samba server.
Files and directories
Table of appear
Contentsas any other files or directories on the local Linux system, although there are
a few differences
in behavior relating to ownership and permissions.[2]
Index
Reviews
Samba Versions 2.2.4 and later have support for Unix CIFS extensions developed by Hewlett-Packard, which add full
Reviews group, and permissions in smbfs filesystems when shared between two Samba systems.
support forReader
Unix ownership,
Errata
You will also need a recent version of smbfs in your Linux kernel.
[2]
Although smbfs is based on the Samba code, it is not itself part of the Samba distribution. Instead, it is
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
included with Linux as a standard part of the Linux filesystem support.
O'Reilly
ThePublisher:
smbmount
and smbmnt programs are part of the Samba distribution and are needed on the client to
mount
Pub Date:
smbfs
February
filesystems.
2003
Samba must be compiled with the --with-smbmount configure option to make
sure these
are compiled. They refer to smb.conf for information they need regarding the local
ISBN: programs
0-596-00256-4
system
and556
network configuration, so you will need a working smb.conf file on the system, even if it is
Pages:
not acting
as
Slots: 1 a Samba server.
If your Linux kernel doesn't include smbfs support, you will get the error message:
ERROR: smbfs filesystem not supported by the kernel
In this case, you must configure and compile a new kernel to include support for
smbfs. When smbfs is installed, and an SMB share is mounted, you can run the
command:
$cat /proc/filesystems
and see a line that looks like:
nodev
smbfs
#mkdir /smb/e
The argument to the -o option might look a little complex. It is a comma-separated list of key=value
pairs. The credentials key is set to the name of the credentials file, which is used to give smbmount a
valid username and password with which to authenticate while connecting to the share. The format is
identical to that used by smbclient (as explained in the previous section), so you can use the same
credentials file for both clients. If you want, you can use the key=value pair username=name%password
to specify the username and password directly in the smbmount command, although this is considerably
less secure.
Table of Contents
Index
Reviews
Thesmbmount command accepts the same authentication methods as smbclient.
Reader
Reviews
The comments
in the section on smbclient regarding supplying passwords on the
Errata
command lineand keeping passwords in files and environment variablesalso
The rest of the options tell smbmount how to translate between the SMB filesystem and the Unix
filesystem,
Publisher: which
O'Reilly differ in their handling of ownership and permissions. The uid and gid options specify
the Pub
owner
and
group
to be assigned to all directories and files in the mounted share.
Date: February
2003
ISBN: 0-596-00256-4
Thefmask and dmask options specify bitmasks for permissions of files and directories, respectively.
Pages: 556
These bitmasks are logically ANDed with whatever permissions are granted by the server to create the
Slots: 1
effective
permissions on the client Unix system. On the server side, the permissions granted depend on
the server's operating system. For a Windows 95/98/Me server using share-mode security, the MS-DOS
read-only attribute can be set on individual files and directories and combined with the Full Access or
Read Only permissions on the share as a whole. In user-level security mode, Windows 95/98/Me can
Using ACL-like
Samba, permissions
Second Edition
is a comprehensive
guideastodiscussed
Samba administration.
This new NT/2000/XP
edition covers
have
applied
to the entire share,
in Chapter 4. Windows
all versions
of on
Samba
from files
2.0 to
2.2,
including with
selected
features Change,
from an alpha
version
of 3.0, that
as well
support
ACLs
individual
and
directories,
Full Control,
or Read
permissions
canas
theapplied
SWAT graphical
configuration
tool.
Updated
Windows
2000,
ME, and XP, are
the whatever
book alsoisexplores
be
to the entire
share. If the
server
is a for
Samba
server,
the permissions
defined
Samba's
new role
as and
a primary
domain
controller
member
server,
its support
for the
usethe
of
by
the Samba
share
the local
Unix system
forand
the domain
individual
files and
directories.
In every
case,
Windows NT/2000/XP
and
filesystem
securitybeyond
on the host
system,for
and
permissions
applied toauthentication
the share act to
further
limit access,
whatUnix
is specified
theaccessing
individual
shared
and printers from Unix clients.
files
andfiles
directories.
You might think that the fmask and dmask permission masks can be used only to
reduce the effective permissions on files and directories, but this is not always the
case. For example, suppose that a file is being shared by a Windows 95/98/Me
server using share-mode security and that some number of users have been given
the Full Access password for the share. If the share is mounted with smbmount
using an fmask of 666, read/write permissions are granted on the Unix system not
only for the owner, but for everyone else on the Unix system as well!
After mounting the \\maya\d share to /smb/e, here is what the contents of /smb/e look like:
$cd /smb/e ; ls -l
total 47
drwxrwxr-x
1 jay
jay
512 Jan
8 20:21 CD-images
drwxrwxr-x
1 jay
jay
512 Jan
6 21:50 lectures
-rw-rw-r--
1 jay
jay
-rw-rw-r--
1 jay
jay
-rw-rw-r--
1 jay
jay
drwxrwxr-x
1 jay
jay
512 Feb
-rw-rw-r--
1 jay
jay
2002 RECYCLED
-rw-rw-r--
1 jay
jay
-rw-rw-r--
1 jay
jay
drwxrwxr-x
1 jay
jay
For the most part, the files and directories contained in the mounted smbfs filesystem will work just like
any others, except for limitations imposed by the nature of SMB networking. For example, not even the
superuser can perform the operation:
Table of Contents
#
lectures
chown root Index
Reviews
chown:
changing
ownership
of 'lectures': Operation not permitted
Reader
Reviews
Errata
because
SMB shares do not intrinsically support the idea of ownership. Some odd behaviors can result
Using Samba, 2nd Edition
from this. For example, the command:
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
does
not produce an error message, although nothing has been changed. The file readme.txt still has
Pub Date: February 2003
permissions set to 664:
ISBN: 0-596-00256-4
#ls
Pages:
556
-l
readme.txt
Slots: 1
-rw-rw-r--
1 jay
jay
Aside from little things such as these, the mounted smbfs filesystem can be used in conjunction with
virtually
any application,
and you
be pleasantly
surprised
at administration.
how nicely it integrates
your
Using Samba,
Second Edition
is a might
comprehensive
guide
to Samba
This newwith
edition
covers
Linux-based
computing
environment.
You
can
even
create
symbolic
links
in
the
Unix
filesystem,
pointing
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as
well as
to
andgraphical
directories
inside SMB tool.
shares.
However,
unless the
server
a Samba
server
thefiles
SWAT
configuration
Updated
for Windows
2000,
ME,isand
XP, the
bookthat
alsosupports
explores
Unix
CIFS
extensions,
you
will
not
be
able
to
create
a
symbolic
link
inside
the
mounted
smbfs
filesystem.
Samba's new role as a primary domain controller and domain member server, its support for the
use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
smbfs
options 0 0
ReplaceShare-UNC with the UNC of the share (using the forward slash format), and replace mount-point
with the name of the directory in the Linux filesystem on which the share will be mounted. In place of
options, simply use the string that you used with the -o flag in the smbmount command.
Once you have found the arguments to use with the smbmount command to mount the share the way
you like it, it is a very simple matter to create the entry for /etc/fstab. The smbmount command we used
to mount the share \\maya\e on /smb/e would translate to this /etc/fstab entry:
//maya/e /smb/e
smbfs
credentials=/home/jay/.smbpw,uid=jay,gid=jay,fmask=664,dmask=775 0 0
If you make a mistake in modifying /etc/fstab, your system might not reboot
properly, and you might be forced to boot into single-user mode to fix the problem.
Before you edit /etc/fstab, be sure to make a backup copy of it, and be prepared to
recover your system if anything goes wrong.
Once the entry has been added, the system will automatically mount the share when booting. Or, the
system administrator can manually mount or unmount the share with commands such as these:
#mount /smb/e
#umount /smb/e
It is possible to use mount and umount by giving them the UNC for the share using
forward slashes, as in our /etc/fstab entry. However, be careful about this. A share
Table
of Contents
might
be listed more than once in /etc/fstab so that it can be mounted at more
Index
than one place in the Linux filesystem. If you use the UNC to specify the share you
Reviews
wish to mount or unmount, you might cause it to be mounted or unmounted at
Reader
Reviews
another
mount point from the one you intended.
Errata
5.4.3
smbmount
ByDavid Common
Collier-Brown, Robert
Eckstein, JayOptions
Ts
Table
5-1 lists
key=value pairs that can be used with the -o option of smbmount or in the options field of
Publisher:
O'Reilly
the/etc/fstab
entry
for the smbfs filesystem. See the smbmount manual page for a complete list of
Pub Date: February 2003
options.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
uid
string or
numeric
gid
string or
numeric
fmask
numeric
dmask
numeric
debug
numeric
Debug level.
workgroup
string
guest
(none)
ro
(none)
Mount read-only.
rw
(none)
ttl
numeric
5.5 smbsh
Thesmbsh program is part of the Samba suite and works on some, but not all, Unix variants. [3]
Effectively, it adds a wrapper around the user's command shell, enabling it and common Unix utilities to
work on files and directories in SMB shares, in addition to files and directories in the local Unix filesystem.
From the user's
perspective,
Table
of Contents the effect is that of a simulated mount of the SMB shares onto the Unix
filesystem.
Index
Reviews
At the time of this writing, smbsh does not work on HP/UX or Linux. However, Linux support might return in the
Reader Reviews
future.
Errata
[3]
Using
Samba,
smbsh
works2nd
byEdition
running the shell and programs run from it in an environment in which calls to the
standard
C
library
redirected
to the
ByDavid Collier-Brownare
, Robert
Eckstein, Jay
Ts smbwrapper library, which has support for operating on SMB
shares. This redirection can work only if the program being run is dynamically linked. Fortunately,
modern Unix versions ship with most common utilities linked dynamically rather than statically.
Publisher: O'Reilly
Slots: 1
To use smbsh, your Samba installation must be configured using the configure option --withsmbwrapper.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
If you have a number of Unix systems with the same host operating system and architecture and don't
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
want to bother with a full Samba installation, you can simply move the following files to the other
Samba's new role as a primary domain controller and domain member server, its support for the use of
systems:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
/usr/local/samba/bin/smbsh
/usr/local/samba/bin/smbwrapper.so
/usr/local/samba/lib/smb.conf
Make sure that /usr/local/samba/bin is in your shell's search path. The smb.conf file is needed only for
smbsh to determine the workgroup or domain and does not need to be as elaborate as your Samba
server's configuration file.
DODO
ARGON
Table ofHANGGLIDE
Contents
Index
BALLET
ReviewsINFUSION
Reader Reviews
CHABLIS
Errata JAZ
MILO
SEAL
OSTRICH
SPARTA
PLAQUE
THEBES
PRAETORIAN
TJ
COBRA
KIKO
RAYOPCI
TRANCE
COUGUR
MACHINE-HEADPCI
RUMYA
VIPERPCI
Publisher: O'Reilly
CRUSTY
Pub Date: February 2003
MATHUMA
SCOT
ISBN: 0-596-00256-4
Likewise,
you
Pages:
556can change your current directory to, and list the contents of, a computer virtual directory,
and then you can see a listing of shares offered by that computer:
Slots: 1
smbsh$cd scot ; ls
ADMIN$
davecb
nc
np2s
pl
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of dhcp-mrk03
Samba from 2.0
features from an alpha version of 3.0, as well as
ace
np to 2.2, including
nps selectedxp
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role
cl
ep as a primary
np2domain controller
opcom and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
fileslowest
and printers
Unixvirtual
clients.directory system. Once you cd into a share, you are within the
This
is the
level offrom
smbsh's
SMB share on the remote computer:
smbsh$cd davecb ; ls
Mail
mkanalysis_dirs.idx
SUNWexplo
nfs.ps
Sent
nsmail
allsun.html
projects.txt
bin
sumtimex
Once in a remote share, most of the Unix shell utilities will work, and you can operate on files and
directories much as you would on any Unix system. You can even create symbolic links in the Unix
filesystem pointing to files and directories in the SMB share. However, attempts to create symbolic links
in the SMB share will fail unless the share is being served by Samba with support for Unix CIFS
extensions.
Table of Contents
Index
Reviews
5.6.1 smbutil
Reader Reviews
Errata
Thesmbutil program
provides functionality similar to some of the Samba suite's command-line utilities. It
Using Samba, 2nd Edition
can be used to list the shares available on an SMB server or perform NetBIOS name lookups.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The first argument given to smbutil is one of a number of subcommands and is usually followed by
arguments
specific to the subcommand. For example, to list the resources offered by a server, use the
Publisher: O'Reilly
view subcommand, and enter your server password when prompted:
Pub Date: February 2003
ISBN:view
0-596-00256-4
%smbutil
//vamana
Pages: 556
Password:
Slots: 1
Share
Type
Comment
------------------------------------------------------------Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
public
diskconfiguration tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT graphical
Samba's new role as a primary domain controller and domain member server, its support for the use of
SS2500
printer
Stylusand
Scan
2500
Windows NT/2000/XP
authentication
filesystem
security on the host Unix system, and accessing
shared files and printers from Unix clients.
IPC$
pipe
IPC Service (Samba 2.2.5)
ADMIN$
disk
leonvs
disk
While starting up, smbutil reads the file .nsmbrc in the user's home directory. Also, the file
/usr/local/etc/nsmb.conf is read, and directives in that file override those in users' ~/.nsmbrc files. This is
to allow administrators to apply mandatory settings to all users. Directives can be placed in this file using
the section and parameter format similar to that of the Samba configuration file. A list of common
configuration parameters is given in Table 5-2.
For example, to keep your password in your ~/.nsmbrc file, you can create an entry in the file such as
the following:
[VAMANA:LEONVS]
Table of Contents
Index
password=$$1625a5723293f0710e5faffcfc6
Reviews
Reader Reviews
The
section heading
Errata in brackets specifies the SMB server's NetBIOS name and the username to which the
subsequent
parameter
Using Samba, 2nd Edition settings apply. (The hostname and username should be supplied in uppercase
characters.) Section headings can also consist of just a hostname or can contain a share name as a third
By
David Collier-Brown
, Robert
Eckstein, Jay
Ts
element
for specifying
parameters
applicable
to a single share. Finally, if a [default] section is present,
the settings in it apply to all connections.
Publisher: O'Reilly
ThePub
following
example
Date: February
2003 .nsmbrc shows some of the other parameters you might use:
ISBN: 0-596-00256-4
[default]
Pages: 556
Slots: 1
username=leonvs
[VAMANA:LEONVS]
password=$$1625a5723293f0710e5faffcfc6
Another thing you can do with smbutil is translate between IP addresses or DNS names and NetBIOS
names. For example, the status subcommand takes an IP address or DNS hostname as an argument and
returns the corresponding SMB server's NetBIOS name and workgroup:
%smbutil status 192.168.1.6
Workgroup: TEST
Server: VAMANA
Thelookup subcommand returns the IP address associated with a given NetBIOS hostname. A NetBIOS
name server can be optionally specified with the -w argument:
%smbutil lookup -w 192.168.1.3 VAMANA
Got response from 192.168.1.3
IP address of VAMANA: 192.168.1.6
5.6.2 mount_smbfs
Themount_smbfs program performs essentially the same function as smbmount on Linux. It mounts an
SMB share on a directory in the local filesystem. The SMB share can then be accessed just like any other
directory, subject to some behavioral differences noted earlier in Section 5.4.1.
The command synopsis for mount_smbfs is:
mount_smbfs
[options]
Share-UNC mount-point
Table of Contents
Index
Reviews
Reader Reviews
//[workgroup;][username[:password]@]server[/share]
Errata
Using
Samba, 2nd Edition
For example:
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
#mount_smbfs '//TEST;leonvs:$$1625a5723293f0710e5faffcfc6@vamana/leonvs' /
Publisher: O'Reilly
\Volumes/leonvs
Pub Date: February 2003
ISBN: 0-596-00256-4
The ownership
and permissions of the mount point determine the default ownership and permissions for
Pages:
556
files and directories
in the mounted share. These can be modified with command-line arguments, like
this: Slots: 1
Configuration file
parameter
Description
-Ihostname
addr
-N
none
-Rcount
retry_count
-Tseconds
timeout
-Uusername
username
-Wworkgroup
workgroup
-dmode
none
-fmode
none
-ggroup
none
-nlong
none
-uusername
none
Table of Contents
-whostname Indexnbns
Reviews
none
password
Reader
Reviews
Errata
5.6.3
Mac OS X
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
In addition to smbutil and mount_smbfs, OS X includes a graphical interface to the functionality they
Publisher: O'Reilly
provide. To use this interface, open the Go menu and select the Connect to Server . . . menu item.
Pub Date: February 2003
Instead
of using a UNC, specify the share in the form of a Uniform Resource Identifier (URI) with a prefix
ISBN:
0-596-00256-4
of smb://
entered
in the Address field, as shown in Figure 5-5.
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
You can specify a server, share, workgroup, username, and password (optionally encrypted with smbutil
crypt) in the URI, in the same format as the UNC argument to mount_smbfs. If you don't specify a share
name in the URI, you will be shown a window that lets you choose from a list of shares available to
mount. See Figure 5-6.
Only guest-accessible shares will show up in the list until you've authenticated. After pressing the
Authenticate button, you'll be prompted for a workgroup, username, and password, as shown in Figure 57. You'll also see this dialog if you provide a share name in the URI, but not a username and password.[4]
[4]
If you've previously stored your authentication information in a Keychain, you will instead be prompted for your
Keychain password.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
As usual
for1Mac OS X, shares are mounted under /Volumes, but show up in the root of the Finder
Slots:
hierarchy.
If you have a WINS server on your network, you can provide the server's IP address in the Directory
Access application, or by using the winsserver parameter in /etc/smb.conf.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
Samba
2.2, including
fromyou
an can
alpha
version
as well as
If you
don't of
know
the from
name2.0
of atoserver
to which selected
you wishfeatures
to connect,
look
for it of
in 3.0,
the browse
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
list, using the graphical frontend to the nmblookup command provided with Samba. Click the downwardSamba's
new role
as aConnect
primarytodomain
member
server, column-based
its support for view
the use
pointing arrow
in the
Server controller
. . . dialogand
boxdomain
to show
a hierarchical,
of of
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
available workgroups and servers, similar to that shown in Figure 5-8. If your client is also acting as an
shared
and it
printers
from Unix
SMB filefiles
server,
won't show
up in clients.
its own browse list.
Table of Contents
Index smbd and nmbd, are controlled through a single ASCII file, smb.conf, that can
Samba's daemons,
Reviews
contain over 300
unique options (also called parameters). Some of these options you will use and change
Reader
Reviews
frequently; others
you
might never use, depending on how much functionality you want Samba to offer
Errata
its clients.
Using Samba, 2nd Edition
This
chapter introduces the structure of the Samba configuration file and shows you how to use options
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
to create and modify disk shares. Subsequent chapters will discuss browsing, how to configure users,
security, printing, and other topics related to implementing Samba on your network.
Publisher: O'Reilly
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
[global]
Reviews
Reader Reviews
workgroup = METRAN
Errata
log
level
= 1
Pub
Date:
February
2003
ISBN: 0-596-00256-4
read only = no
[homes]
Usingbrowsable
Samba, Second
= no Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical= configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
map archive
yes
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
[printers]
shared files and printers from Unix clients.
path = /var/tmp
printable = yes
min print space = 2000
[test]
browsable = yes
read only = yes
path = /usr/local/samba/tmp
This configuration file is based on the one we created in Chapter 2 and sets up a workgroup in which
Samba authenticates users using encrypted passwords and the default user-level security method.
Samba is providing WINS name server support. We've configured very basic event logging to use a log
file not to exceed 1MB in size. The [homes] share has been added to allow Samba to create a disk share
for the home directory of each user who has a standard Unix account on the server. In addition, each
printer registered on the server will be publicly available, as will a single read-only share that maps to the
/usr/local/samba/tmp directory.
[homes]
...
[printers]
...
[test]
Table of Contents
Index
...
Reviews
Reader Reviews
Errata
the share
(or2nd
service)
Using
Samba,
Edition to which the section refers. For example, the [test] and [homes] sections are
unique disk shares; they contain options that map to specific directories on the Samba server. The
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
[printers] share contains options that map to various printers on the server. All the sections defined in
thesmb.conf file, with the exception of the [global] section, will be available as a disk or printer share
Publisher:
O'Reilly
to clients
connecting
to the Samba server.
Pub Date: February 2003
The remaining
lines are individual configuration options for that share. These options will continue until a
ISBN: 0-596-00256-4
new section
is encountered or until the end of the file is reached. Each configuration option follows a
Pages: 556
simpleSlots:
format:
1
option = value
Options in the smb.conf file are set by assigning a value to them. We should warn you up front that some
Using
Second
a comprehensive
to Samba
administration.
This new edition
of
the Samba,
option names
inEdition
Sambaisare
poorly chosen. guide
For example,
read
only is self-explanatory
and is covers
all versions
of Samba
2.0options.
to 2.2, including
selected
from
an alpha
version
ofIt3.0,
well
typical
of many
recentfrom
Samba
The public
optionfeatures
is an older
option
and is
vague.
nowashas
a as
the SWAT graphical
configuration
tool. Updated
for
ME, andAppendix
XP, the book
also explores
less-confusing
synonym
guestok (meaning
it can
beWindows
accessed2000,
by guests).
B contains
an
Samba's newindex
role as
a primary
domain controller
and their
domain
member server, its support for the use of
alphabetical
of all
the configuration
options and
meanings.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
6.1.1.2 Capitalization
Capitalization is not important in the Samba configuration file except in locations where it would confuse
the underlying operating system. For example, let's assume that you included the following option in a
share that pointed to /export/samba/simple :
PATH = /EXPORT/SAMBA/SIMPLE
Samba would have no problem with the path configuration option appearing entirely in capital letters.
However, when it tries to connect to the given directory, it would be unsuccessful because the Unix
filesystemis case-sensitive. Consequently, the path listed would not be found, and clients could not
connect to the share.
Table of Contents
Index
6.1.1.3
Line Reviews
continuation
Reader Reviews
Errata
You can continue
a line in the Samba configuration file using the backslash, like this:
Using Samba, 2nd Edition
comment
= The first
share
that
the primary copies \
ByDavid Collier-Brown
, Robert
Eckstein
, Jay has
Ts
of the new Teamworks software product.
Publisher: O'Reilly
Pub Date:
2003
Because
of February
the backslash,
these two lines will be treated as one line by Samba. The second line begins at
ISBN:
0-596-00256-4 character that Samba encounters; in this case, the o in of.
the first
nonwhitespace
Pages: 556
Slots: 1
6.1.1.4 Comments
You can insert comments in the smb.conf configuration file by starting a line with either a hash (#) or a
Using Samba,
Second
Edition
is a comprehensive
to Samba For
administration.
This
edition
semicolon
( ; ).
For this
purpose,
both characters guide
are equivalent.
example, the
firstnew
three
lines covers
in the
all versions
of Samba
from
to 2.2, including
selected features from an alpha version of 3.0, as well as
following
example
would
be2.0
considered
comments:
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
#
This new
is the
roleprinters
as a primary
section.
domainWe
controller
have given
and domain
a minimum
member
print
server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
;
space
filesofand
2000
printers
to prevent
from Unix
some
clients.
errors that we've seen when
;
[printers]
public = yes
min print space = 2000
Samba will ignore all comment lines in its configuration file; there are no limitations to what can be
placed on a comment line after the initial hash mark or semicolon. Note that the line continuation
character (\) will not be honored on a commented line. Like the rest of the line, it is ignored.
Samba does not allow mixing of comment lines and parameters. Be careful not to
put comments on the same line as anything else, such as:
path = /d # server's data partition
Errors such as this, where the parameter value is defined with a string, can be
tricky to notice. The testparm program won't complain, and the only clues you'll
receive are that testparm reports the path parameter set to /d # server's data
partition, and the failures that result when clients attempt to access the share.
daemons are running. By default, Samba checks the configuration file every 60 seconds. If it finds any
changes, they are immediately put into effect.
Having Samba check the configuration file automatically can be convenient, but it
also means that if you edit smb.conf directly, you might be immediately changing
your network's configuration every time you save the file. If you're making
anything more than a minor change, it may be wiser to copy smb.conf to a
temporary file, edit that, run testparmfilename to check it, and then copy the
Table of Contents
temporary file back to smb.conf. That way, you can be sure to put all your changes
Index
into effect at once, and only after you are confident that you have created the
Reviews
exact configuration you wish to implement.
Reader Reviews
Errata
If you don't want to wait for the configuration file to be reloaded automatically, you can force a reload
Using Samba, 2nd Edition
either by sending a hangup signal to the smbd and nmbd processes or simply by restarting the daemons.
By
David Collier-Brown
Ts
Actually,
it can be a,Robert
good Eckstein
idea to,Jay
restart
the daemons because it forces the clients to disconnect and
reconnect, ensuring that the new configuration is applied to all clients. We showed you how to restart the
daemons
Publisher:
inO'Reilly
Chapter 2, and sending them a hangup (HUP) signal is very similar. On Linux, it can be done
withPub
the
command:
Date:
February 2003
ISBN: 0-596-00256-4
In this Slots:
case,1 not all changes will be immediately recognized by clients. For example, changes to a share
that is currently in use will not be registered until the client disconnects and reconnects to that share. In
addition, server-specific parameters such as the workgroup or NetBIOS name of the server will not go
into effect immediately either. (This behavior was implemented intentionally because it keeps active
Using Samba,
clients
from being
Second
suddenly
Edition
disconnected
is a comprehensive
or encountering
guide to unexpected
Samba administration.
access problems
This new
while
edition
a session
covers
is
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
open.)
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
6.1.2
Variables
shared files and printers from Unix clients.
Because a new copy of thesmbd daemon is created for each connecting client, it is possible for each
client to have its own customized configuration file. Samba allows a limited, yet useful, form of variable
substitution in the configuration file to allow information about the Samba server and the client to be
included in the configuration at the time the client connects. Inside the configuration file, a variable
begins with a percent sign (%), followed by a single upper- or lowercase letter, and can be used only on
the right side of a configuration option (i.e., after the equal sign). An example is:
[pub]
path = /home/ftp/pub/%a
The%a stands for the client system's architecture and will be replaced as shown in Table 6-1.
Replacement string
WfWg
Win95
Windows NT
WinNT
Win2K
Samba
Samba
UNKNOWN
In this example, Samba will assign a unique path for the [pub] share to client systems based on what
operating system they are running. The paths that each client would see as its share differ according to
the client's architecture:
/home/ftp/pub/WfwG
/home/ftp/pub/Win95
/home/ftp/pub/WinNT
Table of Contents
Index
/home/ftp/pub/Win2K
Reviews
Reader Reviews
/home/ftp/pub/Samba
Errata
Using variables in this manner comes in handy if you wish to have different users run custom
configurations based on their own unique characteristics or conditions. Samba has 20 variables, as shown
Publisher: O'Reilly
in Table
6-2.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Variable
Definition
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Client
variables
all
versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT
graphical
configuration
tool.architecture
Updated for(see
Windows
%a
Client's
Table 2000,
6-1) ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
%I
Windows
NT/2000/XP authentication
Client'sand
IP address
filesystem
(e.g.,
security
172.16.1.2)
on the host Unix system, and accessing
shared files and printers from Unix clients.
%m
Client's NetBIOS name
%M
User variables
%u
%U
%H
Home directory of %u
%g
Primary group of %u
%G
Primary group of %U
Share variables
%S
%P
%p
Server variables
%d
%h
%L
%N
%v
Samba version
Miscellaneous variables
%R
%T
%$var
Here's another example of using variables: let's say there are five clients on your network, but one client,
maya, requires a slightly different [homes] configuration. With Samba, it's simple to handle this:
[homes]
Table of Contents
Index
...
Reviews
Reader Reviews
include Errata
= /usr/local/samba/lib/smb.conf.%m
...
Theinclude option here causes a separate configuration file for each particular NetBIOS machine (%m) to
be read
Publisher:
in addition
O'Reilly to the current file. If the hostname of the client system is maya, and if a
smb.conf.maya
file2003
exists in the /usr/local/samba/lib directory, Samba will insert that configuration file
Pub Date: February
into the
default
one. If any configuration options are restated in smb.conf.maya, those values will
ISBN:
0-596-00256-4
override
any
options previously encountered in that share. Note that we say "previously." If any options
Pages:
556
are restated in the main configuration file after the include option, Samba will honor those restated
Slots: 1
values for the share in which they are defined.
If the file specified by the include parameter does not exist, Samba will not generate an error. In fact, it
won't do anything at all. This allows you to create only one extra configuration file for maya when using
Using
Samba, instead
Second of
Edition
is a
comprehensive
Samba administration. This new edition covers
this strategy,
one for
each
client that is guide
on thetonetwork.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical
configuration
tool.
Windows
2000, ME,
and XP,
the
book
Client-specific
configuration
files can
beUpdated
used to for
customize
particular
clients.
They
also
canalso
be explores
used to
Samba's
new roleSamba
as a primary
controller
domain
member
its support
use of
make
debugging
easier.domain
For example,
if weand
have
one client
withserver,
a problem,
we canfor
usethe
this
Windows NT/2000/XP
authentication
and afilesystem
security
on the
hostThis
Unix
system,
and
accessing
approach
to give it a private
log file with
more verbose
logging
level.
allows
us to
see
what Samba
shared
and slowing
printers down
from Unix
clients.
is
doingfiles
without
all the
other clients or overflowing the disk with useless logs.
You can use the variables in Table 6-2 to give custom values to a variety of Samba options. We will
highlight several of these options as we move through the next few chapters.
Table of Contents
Index
Reader Reviews
Errata appears in virtually every Samba configuration file, even though it is not
The[global] section
Using
Samba, There
2nd Edition
mandatory.
are two
purposes for the [global] section. Server-wide settings are defined here, and
By
David
Collier-Brown
, Robert
Jay Ts
any
options
that apply
to Eckstein
shares ,will
be used as a default in all share definitions, unless overridden within
the share definition.
Publisher: O'Reilly
To illustrate this, let's again look at the example at the beginning of the chapter:
Pub Date: February 2003
ISBN: 0-596-00256-4
[global]
Pages: 556
workgroup
Slots: 1
= METRAN
encrypt passwords = yes
support
= yes
Usingwins
Samba,
Second
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
log level
= 1 configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
graphical
Samba's new role as a primary domain controller and domain member server, its support for the use of
max log
size = authentication
1000
Windows
NT/2000/XP
and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
read only = no
[homes]
browsable = no
map archive = yes
[printers]
path = /var/tmp
printable = yes
min print space = 2000
[test]
browsable = yes
read only = yes
path = /usr/local/samba/tmp
When a client connects to the [test] share, Samba first reads the [global] section and sets the option
readonly=no as the global default for each share it encounters throughout the configuration file. This
includes the [homes] and [test] shares. When it reads the definition of the [test] share, it then finds
the configuration option readonly=yes and overrides the default from the [global] section with the
valueyes.
Any option that appears before the first marked section is assumed to be a global option. This means that
the[global] section heading is not absolutely required; however, we suggest you always include it for
clarity and to ensure future compatibility.
Table of Contents
assumes the client
Index is a Unix user trying to connect to her home directory on the server.
Reviews
For example, assume a client system is connecting to the Samba server toltec for the first time and
Reader Reviews
tries to connect to a share named [alice]. There is no [alice] share defined in the smb.conf file, but
Errata
there is a [homes], so Samba searches the password database file and finds an alice user account is
Using Samba, 2nd Edition
present on the system. Samba then checks the password provided by the client against user alice's Unix
By
David Collier-Brown
, Robert
, Jay Ts
passwordeither
with
theEckstein
password
database file if it's using nonencrypted passwords or with Samba's
smbpasswd file if encrypted passwords are in use. If the passwords match, Samba knows it has guessed
right:
the user
alice is trying to connect to her home directory. Samba will then create a share called
Publisher:
O'Reilly
[alice]
for
her,
with
the share's path set to alice's home directory.
Pub Date: February
2003
ISBN: 0-596-00256-4
The process of using the [homes] section to create users (and dealing with their passwords) is discussed
Pages: 556
in more detail in Chapter 9.
Slots: 1
Depending on your system, this file might not be /etc/printcap. You can use the testparm command that comes with
Samba to dump the parameter definitions and determine the value of the printcapname configuration option. The
value assigned to it is the default value chosen when Samba was configured and compiled, which should be correct.
This means that as with [homes], you don't have to maintain a share for each system printer in the
smb.conf file. Instead, Samba honors the Unix printer registry if you ask it to, and it provides the
registered printers to the client systems. However, there is a potential difficulty: if you have an account
namedfred and a printer named fred, Samba will always find the user account first, even if the client
really needed to connect to the printer.
The process of setting up the [printers] share is discussed in more detail in Chapter 10.
Index
Global options must appear in the [global] section and nowhere else. These are options that
Reviews
typically apply to the behavior of the Samba server itself and not to any of its shares.
Reader Reviews
Share options
Errata
Using Samba,
Edition
Share 2nd
options
can
appear in share definitions, the [global] section, or both. If they appear in the
a default behavior for all shares unless a share overrides the
option with a value of its own.
section,
will,Jay
define
ByDavid[global]
Collier-Brown
, Robertthey
Eckstein
Ts
Publisher: O'Reilly
In addition, configuration options can take three kinds of values. They are as follows:
Pub Date: February 2003
ISBN: 0-596-00256-4
Boolean
Pages: 556
These
Slots: 1 are simply yes or no values, but can be represented by any of the following: yes,no,true,
false,1, or 0. The values are case-insensitive: YES is the same as yes.
Numeric
This is a decimal, hexadecimal, or octal number. The standard 0xnn syntax is used for hexadecimal
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
and0nnn for octal.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
String
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
as a
domaincharacters,
controller and
memberorserver,
its support for the use of
Thisnew
is arole
string
ofprimary
case-sensitive
suchdomain
as a filename
a username.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Parameters
Function
Default Scope
config
file
string (name of
file)
None
Global
include
string (name of
file)
None
Global
copy
string (name of
share)
None
Share
For example, the following line instructs Samba to use a configuration file specified by the NetBIOS name
of the client connecting, if such a file exists. If it does, options specified in the original configuration file
are ignored:
[global]
config file = /usr/local/samba/lib/smb.conf.%m
If the configuration file specified does not exist, the option is ignored, and Samba will continue to
Table of Contents
configure itself based on the current file. This allows a default configuration file to serve most clients,
Index
while providing for exceptions with customized configuration files.
Reviews
Reader Reviews
Errata
6.3.1.2
include
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Thisoption, discussed in greater detail earlier, copies the target file into the current configuration file at
the point specified, as shown in Figure 6-1. This option also can be used with variables. You can use this
Publisher:
O'Reilly
option
as follows:
Pub Date: February 2003
[global]
ISBN: 0-596-00256-4
Pages: 556
include = /usr/local/samba/lib/smb.conf.%m
Slots: 1
If the configuration file specified does not exist, the option is ignored. Options in the include file override
any option specified previously, but not options that are specified later. In Figure 6-1, all three options
will override their previous values.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Figure 6-1. The include option in a Samba configuration file
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Theinclude option does not work with the variables %u (user), %P (current share's root directory), or %S
(current share's name) because they are not set at the time the include parameter is processed.
6.3.1.3 copy
Thecopy configuration option allows you to clone the configuration options of the share name that you
specify in the current share. The target share must appear earlier in the configuration file than the share
that is performing the copy. For example:
[template]
writable = yes
browsable = yes
valid users = andy, dave, jay
[data]
path = /usr/local/samba
copy = template
Note that any options in the share that invoked the copy directive will override those in the cloned share;
it does not matter whether they appear before or after the copy directive.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Server
configuration parameters
Reviews
Reader Reviews
workgroup = METRAN
Publisher: O'Reilly
encrypt
passwords
Pub
Date: February
2003
= yes
ISBN: 0-596-00256-4
This configuration file is pretty simple; it advertises the Samba server under the NetBIOS name toltec.
Pages: 556
In addition, it places the system in the METRAN workgroup and displays a description to clients that
Slots: 1
includes
the Samba version number, as well as the NetBIOS name of the Samba server.
If you used the line encrypt passwords = yes in your earlier configuration file,
Using Samba, Second
Edition
comprehensive
guide to Samba administration. This new edition covers
you should
dois
soa here
as well.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
If
you like,
NT/2000/XP
you can goauthentication
ahead and try and
this filesystem
configuration
security
file. Create
on theahost
file named
Unix system,
smb.conf
andunder
accessing
the
shared files and printers
/usr/local/samba/lib
directory
from Unix
with the
clients.
text listed earlier. Then restart the Samba server and use a
Windows client to verify the results. Be sure that your Windows clients are in the METRAN workgroup as
well. After double-clicking the Network Neighborhood on a Windows client, you should see a window
similar to Figure 6-2. (In this figure, Mixtec is another Samba server, and Zapotec is a Windows client.)
You can verify the serverstring by listing the details of the Network Neighborhood window (select
Details in the View menu). You should see a window similar to Figure 6-3.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Using
2nd
Edition
If youSamba,
were to
click
the toltec icon, a window should appear that shows the services that it provides. In
this
case,
the
window
would
be completely
empty because there are no shares on the server yet.
ByDavid Collier-Brown, Robert
Eckstein
, Jay Ts
Publisher: O'Reilly
6.4.1
Server
Configuration
Options
Pub Date:
February
2003
ISBN: 0-596-00256-4
Table Pages:
6-4 summarizes
the server configuration options introduced previously. All three of these options
556
are global
in
scope,
so
they must appear in the [global] section of the configuration file.
Slots: 1
string
Global
server
string
string
Global
Samba %v
6.4.1.2 workgroup
Theworkgroup parameter sets the current workgroup (or domain) in which the Samba server will
advertise itself. Clients that wish to access shares on the Samba server should be in the same NetBIOS
group. Remember that workgroups are really just NetBIOS group names and must follow the standard
NetBIOS naming conventions outlined in Chapter 1.
Table for
of Contents
The default option
this parameter is set at compile time to WORKGROUP. Because this is the default
Index
workgroup name
of every unconfigured Windows and Samba system, we recommend that you always set
Reviews
your workgroup
name in the Samba configuration file. When choosing your workgroup name, try to avoid
making it the Reader
same name
Reviews
as a server or user. This will avoid possible problems with WINS name
resolution.
Errata
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
ThePub
server
string parameter defines a comment string that will appear next to the server name in both
Date: February 2003
the Network
Neighborhood (when shown with the Details view) and the comment entry of the Microsoft
ISBN: 0-596-00256-4
Windows printer manager.[2]
Pages: 556
[2]
Slots:
1
We are
referring here to the window that opens when a printer icon in the Printers control panel is double-clicked.
You can use variables to provide information in the description. For example, our entry earlier was:
[global]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
server string = Samba %v on (%h)
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
The default for this option simply presents the current version of Samba and is equivalent to:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files
and =
printers
server
string
Samba from
%v Unix clients.
Table of Contents
[data]
Index
Reviews
path = /export/samba/data
Reader Reviews
Errata
ByDavid
Collier-Brown
, Robert Eckstein, Jay Ts
volume
= Sample-Data-Drive
writable
= yes
Publisher:
O'Reilly
Pub Date: February 2003
The[data] share is typical for a Samba disk share. The share maps to the directory /export/samba/data
ISBN: 0-596-00256-4
on the Samba server. We've also provided a comment that describes the share as a DataDrive, as well
Pages: 556
as a volume name for the share itself.
Slots: 1
Samba's default is to create a read-only share. As a result, the writable option needs to be explicitly set
for each disk share you wish to make writable.
We
willSamba,
also need
to create
theis/export/samba/data
directory
on the
Samba serverThis
withnew
the edition
following
Using
Second
Edition
a comprehensive guide
to Samba
administration.
covers
commands:
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
#
mkdir /export/samba/data
Samba's
new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
#
chmod files
777 and
/export/samba/data
shared
printers from Unix clients.
Now, if we connect to the toltec server again by double-clicking its icon in the Windows Network
Neighborhood, we will see a single share entitled data, as shown in Figure 6-4. This share has read/write
access, so files can be copied to or from it.
Option
Parameters
Function
Default
Scope
path(directory)
string (directory
name)
/tmp
Share
comment
string
None
Share
Share
name
Share
yes
Share
no
Share
volume
Table of Contents
string
Index
read only
Reviews
Reader Reviews
writable(write
Errataok
or writeable)
Using
Samba, 2nd Edition
boolean
boolean
6.5.1.1
path
Publisher: O'Reilly
Pub Date: February 2003
Thisoption,
which has the synonym directory, indicates the pathname for the root of the shared
ISBN: 0-596-00256-4
directory or printer. You can choose any directory on the Samba server, so long as the owner of the
Pages: 556
Samba process that is connecting has read and write access to that directory. If the path is for a printing
Slots: 1
share, it should point to a temporary directory where files can be written on the server before being
spooled to the target printer ( /tmp and /var/spool are popular choices). If this path is for a disk share,
the contents of the folder representing the share name on the client will match the contents of the
directory on the Samba server.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
The
directory
of specified
Samba from
as the
2.0value
to 2.2,
forincluding
path canselected
be givenfeatures
as a relative
from path,
an alpha
in which
version
case
of it
3.0,
willas
bewell as
the SWAT
relative
to graphical
the directory
configuration
specified by
tool.
theUpdated
rootdirectory
for Windows
parameter.
2000, ME,
Because
and XP,
root
the
directory
book alsodefaults
exploresto
Samba's
root
(/ ), new
it is generally
role as a primary
a good idea
domain
to use
controller
absolute
and
paths
domain
for the
member
path parameter,
server, its support
unless root
for the
directory
use of
Windows
authentication
has
been NT/2000/XP
set to something
other thanand
thefilesystem
default. security on the host Unix system, and accessing
shared files and printers from Unix clients.
6.5.1.2 comment
Thecomment option allows you to enter a comment that will be sent to the client when it attempts to
browse the share. The user can see the comment by using the Details view on the share folder or with
thenet view command at an MS-DOS prompt. For example, here is how you might insert a comment for
a share:
[network]
comment = Network Drive
path = /export/samba/network
Be sure not to confuse the comment option, which documents a Samba server's shares, with the server
string option, which documents the server itself.
6.5.1.3 volume
Thisoption allows you to specify the volume name of the share, which would otherwise default to the
name of the share given in the smb.conf file.
Some software installation programs check the volume name of the distribution CD-ROM to make sure
the correct CD-ROM is in the drive before attempting to install from it. If you copy the contents of the
CD-ROM into a network share and wish to install from there, you can use this option to make sure the
installation program sees the correct volume name:
[network]
Table
of Contents
the same thing,
but they are approached from opposite ends. For example, you can set either of the
Index
following
options
in the [global] section or in an individual share:
Reviews
Reader Reviews
Errata
writable = no
If either option is set as shown, data can be read from a share, but cannot be written to it. You might
think
you would
Publisher:
O'Reillyneed this option only if you were creating a read-only share. However, note that this
read-only
behavior
is the default action for shares; if you want to be able to write data to a share, you
Pub Date: February 2003
must explicitly specify one of the following options in the configuration file for each share:
ISBN: 0-596-00256-4
read
Pages:
only 556
= no
Slots: 1
writable = yes
If you specify more than one occurrence of either option, Samba will adhere to the last value it
encounters
forSecond
the share.
Using Samba,
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Let's
assume that
Indexour Samba server can access both the subnets 192.168.220.* and 134.213.233.*.
Here
are
our
additions
Reader Reviews
Errata
[global]
ISBN: 0-596-00256-4
interfaces = 192.168.220.100/255.255.255.0 \
Pages: 556
Slots: 1
134.213.233.110/255.255.255.0
Take care that you don't explicitly allow a host to access a share, but then deny
access to the entire subnet of which the host is part.
Let's look at another example of that final item. Consider the following options:
hosts allow = 111.222.
hosts deny = 111.222.333.
In this case, only the hosts that belong to the subnet 111.222.*.* will be allowed access to the Samba
shares. However, if a client belongs to the 111.222.333.* subnet, it will be denied access, even though it
still matches the qualifications outlined by hostsallow. The client must appear on the hostsallow list
andmust not appear
the hostsdeny list to gain access to a Samba share.
Table of on
Contents
Index
The
other twoReviews
options that we've specified are interfaces and bindinterfaceonly. Let's look at the
interfaces
option
first. Samba, by default, sends data only from the primary network interface, which in
Reader Reviews
our
example
is
the
192.168.220.100 subnet. If we would like it to send data to more than that one
Errata
interface, we need to specify the complete list with the interfaces option. In the previous example,
Using Samba, 2nd Edition
we've bound Samba to interface with both subnets (192.168.220 and 134.213.233) on which the system
By
Collier-Brown
, Robert Eckstein
, Jay network
Ts
is David
operating
by specifying
the other
interface address: 134.213.233.100. If you have more than
one interface on your computer, you should always set this option, as there is no guarantee that the
Publisher:
O'Reilly that Samba chooses will be the right one.
primary
interface
Pub Date: February 2003
Finally,ISBN:
the 0-596-00256-4
bindinterfacesonly option instructs the nmbd process not to accept any broadcast
messages other than on the subnets specified with the interfaces option. This is different from the
Pages: 556
hostsallow and hostsdeny options, which prevent clients from making connections to services, but not
Slots: 1
from receiving
broadcast messages. Using the bindinterfacesonly option is a way to shut out all
datagrams from foreign subnets. In addition, it instructs the smbd process to bind to only the interface
list given by the interfaces option. This restricts the networks that Samba will serve.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
6.6.1
Networking
Optionstool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
graphical configuration
Samba's new role as a primary domain controller and domain member server, its support for the use of
The
networking
options
we introducedand
earlier
are summarized
Table
6-6.
Windows
NT/2000/XP
authentication
filesystem
security oninthe
host
Unix system, and accessing
shared files and printers from Unix clients.
Parameters
Function
Default
Scope
hosts allow
(allowhosts)
string (list of
hostnames)
None
Share
hosts deny
(denyhosts)
string (list of
hostnames)
Share
interfaces
string (list of
IP/netmask
combinations)
Systemdependent
Global
boolean
no
Global
bind
interfaces
only
Netgroups, which start with an at sign (@), such as @printerhosts. Netgroups are usually available
only on systems running NIS or NIS+. If netgroups are supported on your system, there should be
Table of Contents
anetgroups manual page that describes them in more detail.
Index
Subnets,Reviews
which end with a dot. For example, 130.63.9. means all the systems whose IP addresses
Reader
Reviews
begin with
130.63.9.
Errata
keyword
ALL,
Using The
Samba,
2nd Edition
The keyword EXCEPT followed by one or more names, IP addresses, domain names, netgroups, or
subnets. For example, you could specify that Samba allow all hosts except those on the
Publisher:
O'Reilly subnet with hostsallow=ALL EXCEPT192.168.110. (remember to include the trailing
192.168.110
Pub
Date: February 2003
dot).
ISBN: 0-596-00256-4
Using Pages:
the ALL
556keyword by itself is almost always a bad idea because it means that crackers on any
network
can
Slots: 1 access your Samba server.
The hostname localhost, for the loopback address 127.0.0.1, is included in the hostsallow list by
default and does not need to be listed explicitly unless you have specified the bindinterfacesonly
parameter. This address is required for Samba to work properly.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
to 2.2,
including
features
from an alpha
version
of 3.0,course
as wellofas
Other
than that,
therefrom
is no2.0
default
value
for theselected
hostsallow
configuration
option.
The default
the SWAT
graphical
configuration
Updated
forhosts
Windows
and XP, the
book alsoisexplores
action
in the
event that
neither thetool.
hosts
allow or
deny2000,
optionME,
is specified
in smb.conf
to allow
Samba's
newallrole
as a primary domain controller and domain member server, its support for the use of
access
from
sources.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
If you specify hosts allow in the [global] section, that definition will override any
hosts allow lines in the share definitions. This is the opposite of the usual
behavior, which is for parameters set in share definitions to override default values
set in the [global] section.
In addition, both local browsing propagation and some functions of SWAT require
access to the Samba server through the loopback address and will not work
Table of Contents
correctly if this address is disabled.
Index
Reviews
Reader Reviews
6.6.1.3
interfaces
Errata
Using
Samba, 2nd option
Edition
Theinterfaces
specifies the networks that you want the Samba server to recognize and respond
to.David
ThisCollier-Brown
option is handy
if Eckstein
you have
By
, Robert
, JayaTscomputer that resides on more than one network subnet. If this
option is not set, Samba searches for the primary network interface of the server (typically the first
Ethernet
card) upon startup and configures itself to operate on only that subnet. If the server is
Publisher: O'Reilly
configured for more than one subnet and you do not specify this option, Samba will only work on the first
Pub Date: February 2003
subnet it encounters. You must use this option to force Samba to serve the other subnets on your
ISBN: 0-596-00256-4
network.
Pages: 556
Slots:of1 this option is one or more sets of IP address/netmask pairs, as in the following:
The value
This option might not work correctly if you are using DHCP.
If you set bind interfaces only to yes , add the local host address (127.0.01) to
the "interfaces" list. Otherwise, smbpasswd will be unable to connect to the server
using its default mode in order to change a password, local browse list propagation
will fail, and some functions of swat will not work properly.
Table of Contents
Errata
For
example, the
accounting department might have an accounting server, and clients of it would see
Index
just
the
accounting
disks and printers. The marketing department could have its own server, marketing,
Reviews
with
its
own
reports,
and so on. However, all the services would be provided by one medium-size Unix
Reader Reviews
server (and one relaxed administrator) instead of having one small server per department.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Samba will allow a server to use more than one NetBIOS name with the netbiosaliases option. See
Pub Date: February 2003
Table 6-7.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Thenetbiosaliases option can be used to give the Samba server more than one NetBIOS name. Each
NetBIOS name listed as a value will be displayed in the Network Neighborhood of Windows clients. When
a connection is requested to any of the servers, it will connect to the same Samba server.
This might come in handy, for example, if you're transferring three departments' data to a single Unix
server with larger and faster disks and are retiring or reallocating the old Windows NT/2000 servers. If
the three servers are called sales,accounting, and admin, you can have Samba represent all three
servers with the following options:
[global]
netbios aliases = sales accounting admin
include = /usr/local/samba/lib/smb.conf.%L
SeeFigure 6-5 for what the Network Neighborhood would display from a client. When a client attempts to
connect to Samba, it will specify the name of the server to which it's trying to connect, which is made
available in the configuration file through the %L variable. If the requested server is sales, Samba will
include the file /usr/local/samba/lib/smb.conf.sales . This file might contain global and share declarations
exclusively for the sales team, such as the following:
[global]
workgroup = SALES
hosts allow = 192.168.10.255
[sales2003]
path = /usr/local/samba/sales/sales2003/
...
This particular example would set the workgroup to SALES as well and set the IP address to allow
connections only from the SALES subnet (192.168.10). In addition, it would offer shares specific to the
sales department.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Samba
log filesIndex
can be as brief or verbose as you like. Here is an example of what a Samba log file looks
like:
Reviews
Reader Reviews
Errata
Yielding
connection to IPC$
Pub Date: February 2003
ISBN: 0-596-00256-4
Slots: 1
Transaction
923 of length 49
[global]
log level = 2
log file = /var/log/samba.log.%m
max log size = 50
debug timestamp = yes
Table of Contents
Index a custom log file that reports information up to debug level 2. This is a relatively light
Here, we've added
debugging level.
Reviews
The logging level ranges from 1 to 10, where level 1 provides only a small amount of
information and
levelReviews
10 provides a plethora of low-level information. Levels 2 or 3 will provide us with
Reader
useful debugging
information without wasting disk space on our server. In practice, you should avoid
Errata
using Samba,
log levels
greater than 3 unless you are working on the Samba source code.
Using
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The logging file is located in the /var/log directory thanks to the logfile configuration option. However,
we can use variable substitution to create log files specifically for individual users or clients, such as with
Publisher:
O'Reilly
the%m
variable
in the following line:
Pub Date: February 2003
log file
/usr/local/logs/samba.log.%m
ISBN:=0-596-00256-4
Pages: 556
Isolating the log messages can be invaluable in tracking down a network error if you know the problem is
Slots: 1
coming from a specific client system or user.
We've added a precaution to the log files: no one log file can exceed 50 KB in size, as specified by the
maxlogsize option. If a log file exceeds this size, the contents are moved to a file with the same name
Using
Samba,
Second
is a comprehensive
guide to
Samba
administration.
This
edition
covers
but
with
the suffix
.oldEdition
appended.
If the .old file already
exists,
it is
overwritten and
itsnew
contents
are
lost.
all versions
fromwaiting
2.0 to 2.2,
including
fromThis
an alpha
version
3.0,
as well
as
The
original of
fileSamba
is cleared,
to receive
newselected
logging features
information.
prevents
the of
hard
drive
from
the SWAT
graphical with
configuration
tool.
Updated
for Windows
ME,
and XP, the book also explores
being
overwhelmed
Samba log
files
during the
life of the2000,
Samba
daemons.
Samba's new role as a primary domain controller and domain member server, its support for the use of
We
have decided
to write
the timestamps
of the messages
inon
thethe
logs
with
thesystem,
debugtimestamp
option,
Windows
NT/2000/XP
authentication
and filesystem
security
host
Unix
and accessing
which
is
the
default
behavior.
This
will
place
a
timestamp
in
each
message
written
to
the
logging
file. If
shared files and printers from Unix clients.
we were not interested in this information, we could specify no for this option instead.
/var/log/daemon.log
This specifies that any logging information from system daemons will be stored in the
/var/log/daemon.log file. This is where the Samba information will be stored as well. From there, you can
set a value for the syslog parameter in your Samba configuration file to specify which logging messages
are to be sent to syslog. Only messages that have debug levels lower than the value of the syslog
parameter will be sent to syslog. For example, setting the following:
syslog = 3
specifies that any logging messages with a level of 2 or below will be sent to both syslog and the Samba
logging files. (The mappings to syslog priorities are described in the upcoming section "syslog.") To
continue the example, let's assume that we have set the loglevel option to 4. Logging messages with
levels of 2 and 1 will be sent to both syslog and the Samba logging files, and messages with a level of 3
or 4 will be sent to the Samba logging files, but not to syslog. If the syslog value exceeds the loglevel
value, nothing will be sent to syslog.
If you want to specify that messages be sent only to syslogand not to the standard Samba logging
filesyou can place this option in the configuration file:
syslog only = yes
If this is the case, any logging information above the number specified in the syslog option will be
discarded, as with the loglevel option.
Table of Contents
6.8.2
Logging
Configuration Options
Index
Reviews
Errata
Table
6-8 listsReader
each logging
configuration option that Samba can use.
Reviews
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Option
Parameters
Function
Default
Scope
Specified in
Samba
makefile
Global
ISBN: 0-596-00256-4
Pages: 556
log file
Slots: 1
string (name
of file)
syslog
syslog only
boolean
Global
no
Global
you have a specific problem, you might want to set it at 3, which provides the most useful debugging
information you would need to track down a problem. Levels above 3 provide information that's primarily
for the developers to use for chasing internal bugs, and it slows down the server considerably. Therefore,
we recommend that for normal day-to-day operation, you avoid setting this option to anything above 3.
Table
of Contents
keeps.
When
the
log
file
exceeds this size, the current log file is renamed to add a .old extension (erasing
Index
any
previous
file
with
that
name) and a new debugging log file is started with the original name. For
Reviews
example:
Reader Reviews
[global]
Errata
max log
size
Publisher:
O'Reilly
= 1000
Here, if the size of any log file exceeds 1MB, Samba renames the log file samba.log.machine-name.old,
ISBN: 0-596-00256-4
and a new log file is generated. If there is already a file with the .old extension, Samba deletes it. We
Pages: 556
highly recommend setting this option in your configuration files because debug logging (even at lower
1
levels)Slots:
can quietly
eat away at your available disk space. Using this option protects unwary
administrators from suddenly discovering that most of the space on a disk or partition has been
swallowed up by a single Samba log file.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of Samba
from 2.0
2.2, including
selected features from an alpha version of 3.0, as well as
6.8.2.4
debug
timestamp
or to
timestamp
logs
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
If you happen to be debugging a network problem and you find that the timestamp information within the
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Samba log lines gets in the way, you can turn it off by giving either the timestamplogs or the
shared files and printers from Unix clients.
synonymousdebugtimestamp option a value of no. For example, a regular Samba log file presents its
output in the following form:
12/31/01 12:03:34 toltec (172.16.1.1) connect to server network as user jay
With a no value for this option, the output would appear without the timestamp:
toltec (172.16.1.1) connect to server network as user jay
6.8.2.5 syslog
Thesyslog option causes Samba log messages to be sent to the Unix system logger. The type of log
information to be sent is specified as a numeric value. Like the loglevel option, it can be a number
from 0 to 10. Logging information with a level less than the number specified will be sent to the system
logger. Debug logs greater than or equal to the syslog level, but less than log level, will still be sent to
the standard Samba log files. For example:
[global]
log level = 3
syslog = 1
With this, all logging information with a level of 0 would be sent to the standard Samba logs and the
system logger, while information with levels 1, 2, and 3 would be sent only to the standard Samba logs.
Levels above 3 are not logged at all. All messages sent to the system logger are mapped to a priority
level that the syslogd daemon understands, as shown in Table 6-9. The default level is 1.
syslog priority
LOG_ERR
LOG_WARNING
LOG_NOTICE
Table of Contents
Index
LOG_INFO
LOG_DEBUG
Reader Reviews
use syslog, you will have to run configure--with-syslog when compiling Samba, and
Using
Samba,
you will
need2nd
to Edition
configure your /etc/syslog.conf to suit. (See Section 6.8.1, earlier in this chapter.)
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
6.8.2.6
syslog
only
Publisher:
O'Reilly
Pub Date: February 2003
Thesyslog
option tells Samba not to use its own logging files at all and to use only the system
ISBN:only
0-596-00256-4
logger.
To
enable
this, specify the following option in the global section of the Samba configuration file:
Pages: 556
Slots: 1
[global]
Table of Contents
Index
While name resolution
and browsing are not difficult to configure, some complexity is introduced by the
Reviews
variety of available
name-resolution systems. Historically, Unix and other TCP/IP users have moved from
Errata
choice. Meanwhile, Microsoft has moved from a broadcasting system to a simple, LAN-only name server
Using Samba,
called
WINS 2nd
andEdition
ultimately to DNS.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The reason for going over that history is that all previous systems of name resolution are still in use
today! Finding a host is so crucial to networking that sites want robust (if limited) name-resolution
Publisher: O'Reilly
systems
to fall back on in case the main system fails. Browsing is also complicated by the frequent need
Pub Date:
February
2003 subnets. This chapter shows you how to configure your network to handle name
to show
hosts
in other
ISBN:and
0-596-00256-4
resolution
browsing any way you want.
Pages: 556
Some of
the1 differences between Unix and Microsoft networking implementations are the result of
Slots:
fundamental design goals. Unix networking was originally designed largely to implement a relatively
formal group of systems that were assumed to be small in number, well-maintained, and highly available,
that have static IP addresses, and that wouldn't physically move around from place to place. Bringing a
new server online was a labor-intensive task, but it did not have to be performed frequently. In contrast,
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Windows networking was originally developed as a peer-to-peer collection of small personal computers on
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
a single subnet, having no centrally or hierarchically organized structure.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new roleisas
a primary
domain controller
andtodomain
member
server,
itstime,
support
for the use
of
SMB networking
dynamic.
Computers
are allowed
leave the
network
at any
sometimes
without
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
warning, and also to join or rejoin the network at any time. Furthermore, any user in a Windows network
shared
andshared
printers
from Unix
clients.
can addfiles
a new
resource
to the
network or remove a resource that he had previously added. The
change in the network's configuration is handled automatically by the rest of the network without
requiring a system administrator to take any action.
of Contents
correspondingIndex
to a name, it broadcasted the name to every other system on the network and waited for
Reviews
Reader Reviews
The main problem with performing name resolution using broadcast packets is poor performance of the
Errata
network as a whole, including CPU time consumed by each host on the network, which has to accept
Using Samba, 2nd Edition
every broadcast packet and decide whether to respond to it. Also, broadcast packets usually aren't
By
David Collier-Brown
, Robert
Eckstein
, Jay Ts
forwarded
by routers,
limiting
name
resolution to the local subnet. Microsoft's solution was to add WINS
(Windows Internet Name Service) support to Windows NT so that the computers on the network can
perform
Publisher:
a direct
O'Reillyquery of the WINS server instead of using broadcast packets.
Pub Date: February 2003
Modern
Windows clients use a variety of methods for translating hostnames into IP addresses. The exact
ISBN: 0-596-00256-4
method varies depending on the version of Windows the client is running, how the client is configured
Pages: 556
(i.e., whether DNS server and/or WINS server IP addresses are provided), and whether the application
Slots: 1
software
is accessing the network through Microsoft's Winsock or TCP/IP API. In general, Windows uses
some combination of the following methods:
the name
in its
of recently guide
resolved
names administration. This new edition covers
UsingLooking
Samba,up
Second
Edition
is acache
comprehensive
to Samba
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Querying
DNS servers
the SWAT
graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Using
the DNS Hosts
file
Windows
NT/2000/XP
authentication
and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Querying WINS servers
Using the WINS LMHOSTS file
Performing broadcast name resolution
The first method is pretty much self-explanatory. A hostname is checked against a cache of hostnames
that have been recently resolved to IP addresses. This helps to save time and network bandwidth for
resolving names that are used frequently.
When a Windows system is configured with the IP address of at least one DNS server, it can use DNS to
resolve fully qualified domain names, such as those for sites on the Internet. The DNS servers can be
either Windows NT/2000 or Unix systems. You can learn more about DNS and DNS server configuration
in the O'Reilly book DNS and BIND.
In this chapter, we focus mainly on name resolution using WINS, which is supported by Samba with the
nmbd daemon.
As we explained in Chapter 1, a system can register under more than one NetBIOS name. We use the singular here
only to keep our explanation simple.
When a WINS client joins the network, it registers its NetBIOS name with the WINS server, which stores
it along with the client's IP address in the WINS database. This entry is marked active. The client is then
expected to renew the registration of its name periodically (typically, every four days) to inform the
server that it is still using the name. This period is called the time to live, or TTL. When the client leaves
the network by being shut down gracefully, it informs the server, and the server marks the client's entry
in its database as released.
When a client leaves the network without telling the WINS server to release its name, the server waits
until after it fails to receive the expected registration renewal from the client and then marks the entry as
released.
In either case, the released name is available for use by other clients joining the network. It might persist
in the releasedTable
state
of Contents
in the WINS database, and if it is not reregistered, the entry will eventually be
deleted.
Index
Reviews
More
information
on Reviews
WINS can be found in the Microsoft white paper Windows Internet Naming Service
Reader
(WINS)
Architecture
and Capacity Planning . It can be downloaded from the Microsoft web site at
Errata
http://www.microsoft.com.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
7.1.2
The lmhosts File
Publisher: O'Reilly
Pub Date: February 2003
InChapter 3 we showed you how to configure Windows systems to use the LMHOSTS file as an
ISBN: 0-596-00256-4
alternative to the WINS server for name resolution. Samba also can use an LMHOSTS file, which by
Pages: 556
default is /usr/local/samba/lib/lmhosts. Samba's lmhosts is the same format as the Windows version. A
1
simpleSlots:
lmhosts
file might look like this:
172.16.1.1
toltec
172.16.1.6
maya Edition is a comprehensive guide to Samba administration. This new edition covers
Using Samba, Second
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
The
namesgraphical
on the right
side of thetool.
entries
are NetBIOS
names,
so you
resource
types
to them
the SWAT
configuration
Updated
for Windows
2000,
ME,can
andassign
XP, the
book also
explores
and
add
additional
entries
for
computers:
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
172.16.1.1
toltec#20
shared files and printers from Unix clients.
172.16.1.1
metran#1b
172.16.1.6
maya#20
Here, we've made toltec the primary domain controller of the METRAN domain on the second line. This
line starts with toltec's IP address, followed by the name metran and the resource type <1B>. The
other lines are entries for toltec and maya as standard workstations.
If you wish to place an lmhosts file somewhere other than the default location, you will need to notify the
nmbd process upon startup using the -H option, followed by the name of your lmhosts file, as follows:
#nmbd -H /etc/samba/lmhosts -D
Uses the standard Unix name-resolution methods, which can be /etc/hosts, DNS, NIS, or a
combination, depending on how the local system is configured
wins
Uses the WINS server
bcast
Uses the broadcast method
The order in which
they
are specified is the order in which name resolution will be attempted. In our
Table of
Contents
example, Samba
will attempt to use its WINS server first for name resolution, followed by the lmhosts file
Index
on
the local system.
Reviews Next, the hosts value tells it to use Unix name-resolution methods. The word hosts
can
be
misleading;
covers not only the /etc/hosts file, but also the use of DNS or NIS (as configured on
ReaderitReviews
the
Unix
host).
Finally,
if those three do not work, it will perform a broadcast name resolution.
Errata
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
You can set up Samba as a WINS server by setting the winssupport parameter in the configuration file,
Pub Date: February 2003
like this:
ISBN: 0-596-00256-4
Pages: 556
[global]
Slots: 1
Although this allows Windows clients to resolve fully qualified Internet domain
names through the Samba WINS server, it will work only for domain names that fit
within the 15-character limitation of NetBIOS names. For this reason, we
recommend you use dns proxy only to act as a supplement to your WINS server,
rather than as a replacement for a DNS server.
wins server
172.16.1.1
Table =
of Contents
Index
With this option enabled, Samba will direct all WINS requests to the server located at 172.16.1.1. Note
Reviews
that because the request is directed at a single machine, we don't have to worry about any of the
Reader Reviews
problems inherent in broadcasting. However, Samba will not necessarily use the WINS server before
Thewinssupport and the winsserver parameters are mutually exclusive; you cannot simultaneously
offer
Samba as the WINS server and use another system as the server! Typically, one Samba server is
Publisher: O'Reilly
set up as the WINS server using winssupport, and all other Samba servers are configured with the wins
Pub Date: February 2003
server parameter pointing to the Samba WINS server.
ISBN: 0-596-00256-4
Pages: 556
1
7.1.5.1Slots:
Configuring
a WINS proxy
If you have a Samba server on a subnet that doesn't have a WINS server, and the Samba server has
been configured with a WINS server on another subnet, you can tell the Samba server to forward any
Using
Samba, Second
Edition
a comprehensive
guide to Samba administration. This new edition covers
name-resolution
requests
withisthe
winsproxy option:
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
[global]
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
authentication and filesystem security on the host Unix system, and accessing
wins NT/2000/XP
server = 172.16.200.12
shared files and printers from Unix clients.
wins proxy = yes
Use this only in situations where the WINS server resides on another subnet. Otherwise, the broadcast
will reach the WINS server regardless of any proxying.
Option
Parameters
Function
If set to yes, allows Samba to act as a
WINS server
wins
support
boolean
wins server
wins proxy
boolean
Table of Contents
Index
Reviews
Reader Reviews
Errata
wins hook
dns proxy
string
boolean
Default
Scope
no
Global
None
Global
no
Global
None
Global
no
Global
lmhostshosts
wins bcast
Global
259200 ( 3
days)
Global
518400 (6
days)
Global
name
resolve
string
Publisher: O'Reilly
order
Pub Date: February 2003
ISBN: 0-596-00256-4
max ttl
numeric
Pages: 556
Slots: 1
max wins
ttl
numeric
Minimum TTL
in seconds
for NetBIOS
Using
Samba, Second Edition is a comprehensive
guide
to Samba
administration.21600
This new
min wins
(6 edition covers
numeric
names
given
out
by
Samba
a WINS
Global
all
versions of Samba from 2.0 to 2.2, including selected features as
from
an alpha version
ttl
hours) of 3.0, as well as
server
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
7.1.6.1 wins support
shared files and printers from Unix clients.
Samba will provide WINS name service to all machines in the network if you set the following in the
[global] section of the smb.conf file:
[global]
wins support = yes
The default value is no, which is typically used to allow a Windows NT/2000 server or another Samba
server to be the WINS server. If you enable this option, remember that a Samba WINS server currently
cannot exchange data with other WINS servers, so do not allow any other WINS servers on the network.
When set to yes, this option is mutually exclusive with the winsserver parameter.
report an error. You can specify only one WINS server using this option.
Table You
of Contents
Index
Reviews
[global]
Reader Reviews
wins proxy
= yes
Errata
This option allows you to run a script or other program whenever the WINS database is modified. One
Publisher: O'Reilly
application might be to set up another Samba server to act as a backup for another Samba WINS server.
2003 the winshook script call rsync to synchronize the WINS databases
ThisPub
is Date:
doneFebruary
by having
ISBN:
0-596-00256-4
(/usr/local/samba/var/locks/wins.dat) on the two systems whenever an entry is added or deleted. The
script Pages:
would556
be specified in the Samba configuration file like this:
Slots: 1
[global]
wins hook = /usr/local/bin/sync_wins
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
7.1.6.5
dnsofproxy
all versions
Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new
role
as to
a primary
controller
and
domain
itsset
support
for the use
of
If
you want
the
DNS
be useddomain
if a NetBIOS
name
isn't
found member
in WINS,server,
you can
the following
option:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
dns proxy = yes
This will permit nmbd to query the server's standard DNS. You might wish to deactivate this option if you
do not have a permanent connection to your DNS server. This option should not be used in place of a
DNS server on your network; it is intended for resolving NetBIOS names rather than fully qualified
Internet domain names.
server with the WINS server. You should never need to alter this value.
Table of Contents
7.1.6.9
min wins
Index ttl
Reviews
Reviews
This option is Reader
used when
Samba is providing WINS name service, and it sets the minimum T T L for
NetBIOS names
Errata
registered with Samba. You should never need to alter this value from its default.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
7.2 Browsing
Browsing was developed by Microsoft to help users find shared resources on the network. In a networked
computing environment where users can add or remove shares at any time, it is important to have some
automatic means of keeping track of the shared resources and allowing users to "browse" through them
to find the ones
they
wish to use.
Table
of Contents
Index
Before
browsing
was added to SMB networking, when anyone added a new share, the people with whom
Reviews
they
wished
to
share
the data or printer would have to be informed of the share's UNC, using some
Reader Reviews
relatively low-tech method such as speaking to them in person or over the phone, or sending email.
Errata
Already, this was very inconvenient in large organizations. To further complicate matters, the users
Using Samba, 2nd Edition
working on client computers had to type in the share's UNC to connect to it. The only way to get around
By
David in
Collier-Brown
, Robert
, Jay Ts
typing
the share's
UNC Eckstein
every time
it was used was to map a network drive to it, and with a large
number of shares on the network, this could easily get out of hand.
Publisher: O'Reilly
Pub Date: February 2003
0-596-00256-4
7.2.1 ISBN:
Browsing
in a Windows Network
Pages: 556
Slots:
1
To keep
things
simple, we will first describe network browsing in a network that contains only Windows
systems and then show you how to add a Samba server.
The basic way browsing works is that one computer in the network takes on the role of the master
browser
(also called
local
master
browseguide
master,
or browse
server) and keeps
a list
of all covers
the
Using Samba,
Second
Edition
is a browser,
comprehensive
to Samba
administration.
This new
edition
computers
on
the
local
subnet
that
are
acting
as
SMB
servers.
The
list
of
computers
is
called
the
browse
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
list
includes
all Samba
servers,
Windows
NT/2000/XP
systems,
and and
any XP,
Windows
95/98/Me
systems
the and
SWAT
graphical
configuration
tool.
Updated
for Windows
2000, ME,
the book
also explores
that
have
the
"File
and
printer
sharing
for
Microsoft
Networks"
networking
component
installed.
The
Samba's new role as a primary domain controller and domain member server, its support for the use of
browse
also contains
the names of
all filesystem
workgroups
and domains.
At this
level,
browsing
is limited to
Windowslist
NT/2000/XP
authentication
and
security
on the host
Unix
system,
and accessing
the
local
subnet
because
the
browsing
protocol
depends
on
broadcast
packets,
which
are
typically
not
shared files and printers from Unix clients.
forwarded to other subnets by routers.
A user at any Windows system can view the browse list by opening up the Network Neighborhood (or My
Network Places), as we showed you in Chapter 1. Or, the net view command can be used from a
Windows command prompt:
C:\>net view
Server Name
Remark
------------------------------------------------------------------------------\\MAYA
Windows 98
\\MIXTEC
Samba 2.2.5
\\OLMEC
\\TOLTEC
Samba 2.2.5
\\YAQUI
Windows 95 on mixtec/VMware
\\ZAPOTEC
The command completed successfully.
Then,net view can be used with a computer name as an argument to contact a server directly and list
the resources it is sharing:
Windows 98
Table of Contents
Share
name
Index
Type
Reviews
Reader Reviews
Errata
Used as
Comment
D
E
Disk
Publisher: O'Reilly
Disk
HP
ISBN: 0-596-00256-4
Print
Pages: 556
The command
Slots: 1 completed successfully.
The computers on the network involved in browsing are more than just the master browser and its
clients. There are also backup browsers, which maintain copies of the browse list and respond to client
requests for it. Backup browsers are therefore able to take over the role of master browser seamlessly in
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
case it fails. The master browser usually doesn't serve the browse list directly to clients. Instead, its job
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
is mainly to keep the master copy of the browse list up-to-date, and also periodically update the backup
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
browsers. Clients are expected to get their copies of the browse list from backup browsers, selecting
Samba's new role as a primary domain controller and domain member server, its support for the use of
among them randomly to help to distribute the load on the backup browsers more evenly. Ideally, the
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
interaction between any client and the master browser is limited to the client announcing when it joins or
shared files and printers from Unix clients.
leaves the network (if it is a server) and requesting a list of backup browsers.
There can be more than one backup browser. A workgroup will have a backup browser if two or more
computers are running Windows 95/98/Me or Windows NT Workstation (or another nonserver version of
Windows NT/2000/XP) on the subnet. For every 32 additional computers, another backup browser is
added.
In a Windows NT domain, the primary domain controller is always the local master browser, and if it fails,
another Windows NT/2000 server (if one exists) will take over the role of local master browser. Other
versions of Windows can function as backup browsers, but will never become a master browser if a
Windows NT/2000 server is available.
In addition to acting as the local master browser, the primary domain controller also acts as the domain
master browser, which ties subnets together and allows browse lists to be shared between master and
backup browsers on separate subnets. This is how browsing is extended to function beyond the local
subnet. Each subnet functions as a separate browsing entity, and the domain master browser
synchronizes the master browsers of each subnet. In a Windows-only network, browsing cannot function
across subnets unless a Windows NT/2000 PDC exists on the network. Samba can act as a domain
master browser and can perform that task even in a workgroup network, which means that the Windows
PDC is not required for this task. (It is also possible to use the remotebrowsesync parameter to
configure a Samba server to synchronize its browse list with a Samba server on another subnet. In this
case, each server must be acting as the local master browser of its subnet.)
Unless it is configured never to act as a browser, each computer on the subnet is considered a potential
browser and can be ordered by the browse master to become a backup browser, or it can identify itself
as a backup browser and accept the role on its own.
among themselves in a process called an election. An election is started by a computer in the subnet
when it discovers that no master browser is currently running. If a master browser is shut down
gracefully, it will broadcast an election request datagram, initiating an election by the remaining
computers. If the master browser fails, the election can be started by a client computer that requests a
list of backup browsers from the master browser or by a backup browser that requests to have its browse
list updated from the master browser. In each case, the system fails to receive a reply from the master
browser and initiates the election.
Browser elections are decided in multiple rounds of self-elimination. During each round, potential
Table ofelection
Contents request datagrams containing their qualifications to notify other potential
browsers broadcast
potential browser receives an election request datagram from a more qualified opponent, it
drops out, disqualifying
itself from becoming the master browser. Otherwise, it responds with its own
Reader Reviews
election request
datagram. After a few rounds, only one potential browser is left in the election. After an
Errata
additional
four
Using
Samba,
2ndrounds
Edition of sending out an election request datagram and receiving no response, it
becomes the master browser and sends a broadcast datagram announcing itself as the local master
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
browser for the subnet. It then assigns runners-up in the election as backup browsers, as needed.
Publisher: browser's
O'Reilly
A potential
qualifications include the following:
Pub Date: February 2003
ISBN: 0-596-00256-4
Slots: 1
The
version of the election protocol it is running
Value
32
16
Windows 95/98/Me
Role
Value
128
WINS client
32
Preferred master
Running master
browser
Recent backup
Table
of Contents
Backup browser
Index
Reviews
Reader Reviews
The operating-system type is compared first, and the system with the highest value wins. The values
Errata
have been chosen
to cause the primary domain controller, if there is one, to become the local master
Using Samba, 2nd Edition
browser. Otherwise, a Windows NT/2000/XP system will win over a Windows for Workgroups or Windows
By
David Collier-Brown
95/98/Me
system. ,Robert Eckstein,Jay Ts
When
an operating-system type comparison results in a tie, the role of the computer is compared. A
Publisher: O'Reilly
computer can have more than one of the values in Table 7-3, in which case the values are added.
Pub Date: February 2003
ISBN: 0-596-00256-4
A domain
master browser has a role value of 128 to weight the election so heavily in its favor that it will
Pages:
also become556
the local master browser on its own subnet. Although the primary domain controller (which
Slots:
1 domain master browser) will win the election based solely on its operating system value,
is always
the
sometimes there is no primary domain controller on the network, and the domain master browser would
not otherwise be distinguished from other potential browsers.
Systems
that are
usingEdition
a WINS
for name resolution
are weighted
heavily over
usecovers
Using Samba,
Second
is server
a comprehensive
guide to Samba
administration.
Thisones
new that
edition
broadcast
name
resolution
with
a
role
value
of
32.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Apreferred master is a computer that has been selected and configured manually by a system
Samba's new role as a primary domain controller and domain member server, its support for the use of
administrator to be favored as the choice master browser. When a preferred master starts up, it forces a
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
browser election, even if an existing master browser is still active. A preferred master has a role value of
shared files and printers from Unix clients.
8, and the existing master browser gets a value of 4.
A backup browser that has recently been a master browser and still has an up-to-date browse list is given
a role value of 2, and a potential browser that has been running as a backup browser gets a value of 1.
If comparing the operating-system type and role results in a tie, the computer that has been running the
longest wins. In the unlikely event that the two have been up for the same amount of time, the computer
that wins is the one with the NetBIOS name that sorts first alphabetically.
You can tell if a machine is a local master browser by using the Windows nbtstat command. Place the
NetBIOS name of the machine you wish to check after the -a option:
C:\>nbtstat -a toltec
Name
Type
Status
--------------------------------------------TOLTEC
<00>
UNIQUE
Registered
TOLTEC
<03>
UNIQUE
Registered
TOLTEC
<20>
UNIQUE
Registered
..__MSBROWSE__.<01>
GROUP
Registered
METRAN
<00>
GROUP
Registered
<1B>
UNIQUE
Registered
<1C>
GROUP
Registered
UNIQUE
Registered
GROUP
Registered
METRAN
METRAN
METRAN
Table of Contents
Index
Reviews
Reader Reviews
<1D>
Errata
UsingMETRAN
Samba, 2nd Edition <1E>
Publisher: O'Reilly
ISBN: 0-596-00256-4
The resource
entry that you're looking for is .._ _MSBROWSE_ _.<01>. This indicates that the server is
Pages:
556 as the local master browser for the current subnet. If the machine is a Samba server,
currently acting
Slots:
1
you can
check
the Samba nmbd log file for an entry such as:
nmbd/nmbd_become_lmb.c:become_local_master_stage2(406)
*****
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Samba
name
server configuration
TOLTEC is now
local master
browser
forME, and XP, the book also explores
the SWAT
graphical
tool.a Updated
for Windows
2000,
Samba's new role as a primary domain controller and domain member server, its support for the use of
workgroup
METRAN onauthentication
subnet 172.16.1.0
Windows NT/2000/XP
and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Or, you can use the nmblookup command with the -M option and the workgroup or domain name on any
Samba server to find the IP address of the local master:
$nmblookup -M metran
querying metran on 172.16.1.255
172.16.1.1 metran<1d>
Table of Contents
local master
= no
Index
Reviews
Usually, you will want Samba to be available as a local master or at least a backup browser. In the
Reader Reviews
simplest case, you don't need to do anything because Samba's default is to participate in browsing
os level = 33
ISBN: 0-596-00256-4
Pages: 556 value
preceding
The
will allow Samba to beat even a Windows 2000 Advanced Server acting as a primary
1
domainSlots:
controller.
As we show in the following section, though, forcing Samba to win this way is not
recommended.
If you want to allow a Windows XP Professional system to be the master browser, you would need to set
Samba
lower: Second Edition is a comprehensive guide to Samba administration. This new edition covers
Using Samba,
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
[global]
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
os level = 8
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files andvalue
printers
from
Unix
The maximum
for os
level
is clients.
255 because it is handled as an 8-bit unsigned integer. Supposing we
wanted to make absolutely sure our Samba server will be the local master browser at all times, we might
say:
[global]
local master = yes
os level = 255
preferred master = yes
The addition of the preferredmaster parameter causes Samba to start a browser election as soon as it
starts up, and the oslevel of 255 allows it to beat any other system on the network. This includes other
Samba servers, assuming they are configured properly! If another server is using a similar configuration
file (with oslevel=255 and preferredmaster=yes), the two will fight each other for the master
browser role, winning elections based on minor criteria, such as uptime or their current role. To avoid
this, other Samba servers should be set with a lower oslevel and not configured to be the preferred
master.
There is no election to determine which machine assumes the role of the domain master browser.
Instead, the administrator has to set it manually. By Microsoft design, however, the domain master
browser and the PDC both register a resource type of <1B>, so the rolesand the machinesare
inseparable.
If you have a Windows NT server on the network acting as a PDC, we recommend that you do not try to
use Samba to become the domain master browser. The reverse is true as well: if Samba is taking on the
responsibilities of a PDC, we recommend making it the domain master browser as well. Although it is
possible to split the roles with Samba, this is not a good idea. Using two different machines to serve as
Table
of Contents
the PDC and the
domain
master browser can cause random errors to occur in a Windows workgroup.
Index
Reviewsthe role of a domain master browser for all subnets in the workgroup with the
following options:
Reader Reviews
[global]
Errata
= yes
local
master = yes
ISBN: 0-596-00256-4
Pages: 556
os level = 255
Slots: 1
The final three parameters ensure that the server is also the local master browser, which is vital for it to
work properly as the domain master browser. You can verify that a Samba machine is in fact the domain
master browser by checking the nmbd log file:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
nmbd/nmbd_become_dmb.c:become_domain_master_stage2(118)
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
*****
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared name
Samba
files and
server
printers
TOLTEC
fromis
Unix
now
clients.
a domain master browser for
workgroup METRAN on subnet 172.16.1.0
Or you can use the nmblookup command that comes with the Samba distribution to query for a unique
<1B> resource type in the workgroup:
#nmblookup METRAN#1B
Sending queries to 172.16.1.255
172.16.1.1 METRAN<1b>
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
First, a Samba server that is a local master browser can use the remoteannounce configuration option to
Slots: 1
make sure
that computers in different subnets are sent broadcast announcements about the server. This
has the effect of ensuring that the Samba server appears in the browse lists of foreign subnets. To
achieve this, however, the directed broadcasts must reach the local master browser on the other subnet.
Be aware that many routers do not allow directed broadcasts by default; you might have to change this
Using Samba,
Edition
is a comprehensive
to Samba
This new edition covers
setting
on the Second
router for
the directed
broadcasts toguide
get through
to administration.
its subnet.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
With
the remote
announce
option, list
the
subnets
and
the workgroup
that
should
receive
the SWAT
graphical
configuration
tool.
Updated
for
Windows
2000, ME,
and
XP, the
bookthe
alsobroadcast.
explores
Samba's
For
example,
new to
role
ensure
as a primary
that machines
domainincontroller
the 172.16.2
and domain
and 172.16.3
member
subnets
server,
and
its the
support
METRAN
for the
workgroup
use of
Windows
are
sent broadcast
NT/2000/XP
information
authentication
from our
andSamba
filesystem
server,
security
we could
on the
specify
host Unix
the following:
system, and accessing
shared files and printers from Unix clients.
[global]
remote announce = 172.16.2.255/METRAN \
172.16.3.255/METRAN
Instead of supplying a broadcast address of the remote subnet, you are allowed to specify the exact
address where broadcasts should be sent if the local master browser on the foreign subnet is guaranteed
to always have the same IP address.
A Samba local master browser can synchronize its browse list directly with one or more Samba servers,
each acting as a local master browser on a different subnet. This is another way to implement browsing
across subnets. For example, let's assume that Samba is configured as a local master browser, and
Samba local master browsers exist at 172.16.2.130 and 172.16.3.120. We can use the remotebrowse
sync option to sync directly with the Samba servers, as follows:
[global]
remote browse sync = 172.16.2.130 172.16.3.120
For this to work, the other Samba machines must also be local master browsers. You can also use
directed broadcasts with this option if you do not know specific IP addresses of local master browsers.
[data]
path = /export/samba/userdata
browsable = no
Although you typically don't want to do this to an ordinary disk share, the browsable option is useful in
the event that you need to create a share with contents that you do not want others to see, such as a
[netlogon] share for storing logon scripts for Windows domain control (see Chapter 4 for more
of Contents
information onTable
logon
scripts).
Index
Another example
is the [homes] share. This share is often marked nonbrowsable so that a share named
Reviews
[homes] won'tReader
appear
when its machine's resources are browsed. However, if a user alice logs on and
Reviews
looks
at the machine's
shares, an [alice] share will appear under the machine.
Errata
Using Samba, 2nd Edition
What if we wanted to make sure alice's share appeared to everyone before she logs on? This could be
By
David
Collier-Brown
, Robert
, Jayoption.
Ts
done
with
the global
autoEckstein
services
This option preloads shares into the browse list to ensure
that they are always visible:
Publisher: O'Reilly
[global]
Pub Date: February
2003
ISBN: 0-596-00256-4
Parameters
Function
Default
Scope
announce as
string
N T
Server
Global
announceversion
numeric
4.5
Global
browsable
(browseable)
Boolean
yes
Share
browse list
Boolean
yes
Global
auto services
(preload)
None
Global
defaultservice
(default)
None
Global
local master
Boolean
yes
Global
lm announce
yes,no, or auto
Global
lm interval
numeric
Global
60
preferredmaster
Boolean
(prefered master)
no
Global
Boolean
no
Global
domain master
os level
Table of Contents
numeric
Index
remote browse
Reviews string (list of IP
sync
Reader Reviews
addresses)
Global
None
Global
Global
Errata
(IP
address/workgroup
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
pairs)
remoteannounce
Publisher: O'Reilly
7.2.7.1
announce
as
Pub Date:
February 2003
ISBN: 0-596-00256-4
This global
option specifies the type of operating system that Samba announces to other
Pages: configuration
556
machines
on
the
network.
The default value for this option is N TServer, which causes Samba to
Slots: 1
masquerade as a Windows NT Server operating system. Other possible values are NT,NTWorkstation,
Win95, and W f W for a Windows for Workgroup operating system. You can override the default value
with the following:
Using
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
[global]
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
tool. Updated for Windows 2000, ME, and XP, the book also explores
announce
as = configuration
Win95
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
filesystem
on the hostoption.
Unix system, and accessing
We
recommend
against
changing theand
default
value ofsecurity
this configuration
shared files and printers from Unix clients.
7.2.7.3 browsable
Thebrowsable option (also spelled browseable) indicates whether the share referenced should appear in
the list of available resources for the system on which it resides. This option is always set to yes by
default. If you wish to prevent the share from being seen in a client's browser, you can reset this option
tono.
Note that this does not prevent someone from accessing the share using other means, such as specifying
a UNC location (e.g., \\server\accounting) in Windows Explorer. It only prevents the share from being
listed under the system's resources when being browsed.
You should never need to change this parameter from its default value of yes. If your Samba server is
acting as a local master browser (i.e., it has won the browsing election), you can use the global browse
list option to instruct Samba to provide or withhold its browse list to all clients. By default, Samba
always provides a browse list. You can withhold this information by specifying the following:
[global]
browse list = no
If you disable Table
the browse
of Contents
list, clients cannot browse the names of other machines, their services, and
other domainsIndex
currently available on the network. Note that this won't make any particular machine
inaccessible; ifReviews
someone knows a valid machine name/address and a share on that machine, he can still
connect to it explicitly
using the Windows net use command or by mapping a drive letter to it using
Reader Reviews
Windows Explorer.
Errata It simply prevents information in the browse list from being retrieved by any client
that requests
it. Edition
Using
Samba, 2nd
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The global autoservices option, which is also called preload, ensures that the specified shares are
ISBN: 0-596-00256-4
always visible in the browse list. One common use for this option is to advertise specific user or printer
Pages:
shares that 556
are created by the [homes] or [printers] shares, but are not otherwise browsable.
Slots: 1
This option works best with disk shares. If you wish to force each of your system printers (i.e., those
listed in the printer capabilities file) to appear in the browse list, we recommend using the loadprinters
option instead.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Shares
listed
the from
autoservices
will not
be displayed
the browse
list
optionofis3.0,
set as
to well
no. as
all versions
ofwith
Samba
2.0 to 2.2,option
including
selected
featuresiffrom
an alpha
version
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
7.2.7.6
service
Windowsdefault
NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
The global defaultservice option (sometimes called default) names a "last-ditch" share. The value is
set to an existing share name without the enclosing brackets. When a client requests a nonexistent disk
or printer share, Samba will attempt to connect the user to the share specified by this option instead. The
option is specified as follows:
[global]
default service = helpshare
When Samba redirects the requested, nonexistent service to the service specified by defaultservice,
the%S option takes on the value of the requested service, with any underscores ( _ ) in the requested
service replaced by forward slashes (/).
7.2.7.8 lm announce
The global lmannounce option tells Samba's nmbd whether to send LAN Manager host announcements
on behalf of the server. These host announcements might be required by older clients, such as IBM's
OS/2 operating system. This announcement allows the server to be added to the browse lists of the
client. If activated, Samba will announce itself repetitively at the number of seconds specified by the lm
interval option.
You can specify the option as follows:
[global]
lm announce = yes
This
configuration
takes the standard Boolean values, yes and no, which enable or disable LAN
Table option
of Contents
Manager
announcements,
respectively. In addition, a third option, auto, causes nmbd to listen passively
Index
for
LAN
Manager
announcements,
but not to send any of its own initially. If LAN Manager announcements
Reviews
are
detected
for
another
machine
on
the network, nmbd will start sending its own LAN Manager
Reader Reviews
announcements to ensure that it is visible. The default value is auto. You probably won't need to change
Errata
this
value from its default.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
7.2.7.9 lm interval
Publisher: O'Reilly
Date: February 2003
ThisPub
option,
which is used in conjunction with lmannounce, indicates the number of seconds nmbd will
ISBN: 0-596-00256-4
wait before repeatedly broadcasting LAN Manager-style announcements. LAN Manager announcements
Pages:
556
must be
enabled
for this option to work. The default value is 60 seconds. If you set this value to 0,
SambaSlots:
will 1not send any LAN Manager host announcements, regardless of the value of the lmannounce
option. You can reset the value of this option as follows:
[global]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
lm interval
= 90
all versions
of Samba
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new
role as master
a primary domain controller and domain member server, its support for the use of
7.2.7.10
preferred
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and
printers
fromrequests
Unix clients.
The
preferred
master
option
that Samba set the preferred master bit when participating in an
election. This gives the server a higher preferred status in the workgroup than other machines at the
same operating-system level. If you are configuring your Samba machine to become the local master
browser, it is wise to set the following value:
[global]
preferred master = yes
Otherwise, you should leave it set to its default, no. If Samba is configured as a preferred master
browser, it will force an election when it first comes online.
7.2.7.12 os level
The global oslevel option defines the operating-system value with which Samba will masquerade during
a browser election. If you wish to have Samba win an election and become the master browser, set the
oslevel higher than that of any other system on the subnet. The values are shown in Table 7-2. The
default level is 20, which means that Samba will win elections against all versions of Windows, except
Windows NT/2000 if it is operating as the PDC. If you wish Samba to win all elections, you can set its
operating system value as follows:
Table of Contents
[global]
Index
Reviews
os levelReader
= 255Reviews
Errata
The global remotebrowsesync option specifies that Samba should synchronize its browse lists with local
master
Publisher:
browsers
O'Reilly in other subnets. However, the synchronization can occur only with other Samba
servers
andFebruary
not with
Windows computers. For example, if your Samba server were a master browser on
Pub Date:
2003
the subnet
172.16.235,
ISBN: 0-596-00256-4 and Samba local master browsers existed on other subnets located at
172.16.234.92
and 172.16.236.2, you would specify the following:
Pages: 556
Slots: 1
[global]
Table of Contents
(oplocks), connection scripts, supporting Microsoft Dfs (Distributed filesystem) shares, and using NIS
Index
home directories.
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
8.1.1 Hiding
and Vetoing Files
Reader Reviews
Errata
Sometimes you
need to ensure that a user cannot see or access a file at all. Other times, you don't want
Using Samba, 2nd Edition
to keep users from accessing a fileyou just want to hide it when they view the contents of the directory.
By
Collier-Brown
, Robert
, Jay
OnDavid
Windows
systems,
an Eckstein
attribute
ofTsfiles allows them to be hidden from a folder listing. With Unix, the
traditional way of hiding files in a directory is to use a dot (.) as the first character in the filename. This
prevents
items
such as configuration files from being seen when performing an ordinary ls command.
Publisher:
O'Reilly
Keeping
a
user
from accessing a file at all, however, involves working with permissions on files and
Pub Date: February 2003
directories.
ISBN: 0-596-00256-4
Pages:
556
first
option
The
we should discuss is the Boolean hidedotfiles. When it is set to yes, Samba reports
Slots: 1
files beginning
with a period (.) as having their hidden attribute set. If the user has chosen to show all
hidden files while browsing (e.g., using the Folder Options menu item under the View menu in Windows
98), he will still be able to see the files, although his icons will appear "ghosted," or slightly grayed-out. If
the client is configured not to show hidden files, the files will not appear at all.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Instead
of simply
hiding
files
beginning
with a dot,
you can
also specify
a string
all versions
of Samba
from
2.0
to 2.2, including
selected
features
from an
alpha pattern
version to
of Samba
3.0, as for
wellfiles
as
to
hide,
using
the
hide
files
option.
For
example,
let's
assume
you
specified
the
following
in
our
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
example
share:
Samba's[data]
new role
as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
[data]
shared files and printers from Unix clients.
hide files = /*.java/*README*/
Each entry for this option must begin, end, or be separated from another with a slash ( / ) character,
even if only one pattern is listed. This convention allows spaces to appear in filenames. The slashes have
nothing to do with Unix directories; they are instead acting as delimiters for the hidefiles values.
If you want to prevent users from seeing files completely, you can instead use the vetofiles option.
This option, which takes the same syntax as the hidefiles option, specifies a list of files that should
never be seen by the user. For example, let's change the [data] share to the following:
[data]
veto files = /*.java/*README*/
The syntax of this option is identical to the hidefiles configuration option: each entry must begin, end,
or be separated from another with a slash (/) character, even if only one pattern is listed. If you do so,
files that match the pattern, such as hello.java and README.txt, will simply disappear from the directory,
and the user cannot access them through SMB.
We need to address one other question. What happens if the user tries to delete a directory that contains
vetoed files? This is where the deletevetofiles option comes in. If this Boolean option is set to yes,
the user can delete both the regular files and the vetoed files in the directory, and the directory itself is
removed. If the option is set to no, the user cannot delete the vetoed files, and consequently the
directory is not deleted either. From the user's perspective, the directory appears empty, but cannot be
removed.
Thedontdescend directive specifies a list of directories whose contents Samba should not make visible.
Note that we say contents, not the directory itself. Users can enter a directory marked as such, but they
are prohibited from descending the directory tree any fartherthey always see an empty folder. For
example, let's use this option with a more basic form of the share that we defined earlier in the chapter:
[data]
dont descend = config defaults
In addition, let's assume that the /home/samba/data directory has the following contents:
drwxr-xr-x
drwxr-xr-x
6 tom
users
8 root
root
Table of Contents
-rw-r--r-
2 tom
Index
Reviews
drwxr-xr-x
3 tomReviews users
Reader
Errata
drwxr-xr-x
tom
Using Samba, 2nd3Edition
users
users
drwxr-xr-x
3 tom
users
1024 Jun
9 11:43 README
Publisher:
O'Reilly
If the
user then
connects to the share, she would see the directories in the share. However, the contents
of the
Pub /config
Date: February
and /defaults
2003
directories would appear empty to her, even if other folders or files existed in
them. ISBN:
In addition,
users cannot write any data to the folder (which prevents them from creating a file or
0-596-00256-4
folder Pages:
with the
556 same name as one that is already there but invisible). If a user attempts to do so, she will
receive an "Access Denied" message. The dontdescend option is an administrative optionnot a security
Slots: 1
optionand is not a substitute for good file permissions.
8.1.2
LinksSecond Edition is a comprehensive guide to Samba administration. This new edition covers
Using Samba,
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
tool. link
Updated
for Windows
ME,
and XP,
the book
also explores
When
a client
tries to
open a symbolic
on a Samba
server2000,
share,
Samba
attempts
to follow
the link to
Samba's
newfile
role
aslet
a primary
domain
controller
member
itsIfsupport
for want
the use
find
the real
and
the client
open it,
as if theand
userdomain
were on
a Unix server,
machine.
you don't
to of
Windows
allow
this,NT/2000/XP
set the follow
authentication
symlinks option
and filesystem
like this: security on the host Unix system, and accessing
shared files and printers from Unix clients.
[data]
follow symlinks = no
You can test this by setting up and trying to access a symbolic link. Create a directory on the Unix server
inside the share, acting as the user under which you will log in to Samba. Enter the following commands:
$echo "This is a test" >hello.txt
$ln -s hello.txt hello-link.txt
This results in the text file hello.txt and a symbolic link to it called hello-link.txt. Normally, if you doubleclick either one, you will receive a file that has the text "This is a test" inside of it. However, with the
followsymlinks option set to no, you will receive an error dialog if you double-click hello-link.txt.
Thewidelinks option, if set to no, prevents the client user from following symbolic links that point
outside the shared directory tree. For example, let's assume that we modified the [data] share as
follows:
[data]
follow symlinks = yes
wide links = no
As long as the followsymlinks option is disabled, Samba will refuse to follow any symbolic links outside
the current share tree. If we create a file outside the share (for example, in someone's home directory)
and then create a link to it in the share as follows:
ln -s ~tom/datafile ./datafile
Table of Contents
Index
Reviews
Table
Reader Reviews
Errata
UsingOption
Samba, 2nd Edition
Parameters
Function
Default Scope
dont descend
string (list of
directories)
None
Share
yes
Share
Boolean
yes
Global
Boolean
yes
Share
Publisher: O'Reilly
follow
Pub Date: February
2003
Boolean
symlinks
ISBN: 0-596-00256-4
Pages:
556
getwd
cache
Slots: 1
wide links
hide dot
If set to yes, treats Unix hidden files as hidden
yes
Boolean
Share
filesSamba, Second Edition is a comprehensive
Using
files in Windows.
guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
hide files
string
(list of files)tool.
ListUpdated
of file patterns
to treat
as hidden.
Share
the SWAT graphical
configuration
for Windows
2000,
ME, and XP, the bookNone
also explores
Samba's
new role
as a (list
primary
domain
and domain
member
for the use
of
veto files
string
of files)
Listcontroller
of file patterns
to never
show. server, its supportNone
Share
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
deletefiles
veto
If set to yes, will delete files matched by veto
shared
and Boolean
printers from Unix clients.
no
Share
files
files when the directory they reside in is deleted.
Contents
Index
Reviews
Errata
8.1.3.5
hide Reader
dot files
Reviews
Thehide
dotfiles
option hides any files on the server that begin with a dot (.) character to mimic the
Using
Samba,
2nd Edition
functionality behind several shell commands that are present on Unix systems. Like hidefiles, those
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
files that begin with a dot have the DOS hidden attribute set, which doesn't guarantee that a client cannot
view them. The default value for this option is yes.
Publisher: O'Reilly
Pub Date: February 2003
0-596-00256-4
8.1.3.6ISBN:
hide
files
Pages: 556
Slots:
1
Thehide
files
option provides one or more directory or filename patterns to Samba. Any file matching
this pattern will be treated as a hidden file from the perspective of the client. Note that this simply means
that the DOS hidden attribute is set, which might or might not mean that the user can actually see it
while browsing.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Each
entry in
list must
or be separated
from
another
entry
with aversion
slash (/)
all versions
of the
Samba
from begin,
2.0 to end,
2.2, including
selected
features
from
an alpha
of character,
3.0, as well as
even
if only
one pattern
is listed. This
spaces
to appear2000,
in theME,
list.and
Asterisks
bealso
usedexplores
as a
the SWAT
graphical
configuration
tool.allows
Updated
for Windows
XP, thecan
book
wildcard
represent
or more
characters.
Questions
marks
can beserver,
used toits
represent
one of
Samba's to
new
role as azero
primary
domain
controller
and domain
member
support exactly
for the use
character.
For example:
Windows NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
hide files = /.jav*/README.???/
Table of
Contents
Index
Errata
Let's
take a look
at how Unix assigns permissions. All Unix files have read, write, and execute bits for
Reviews
three
classifications
of users: owner, group, and world. These permissions can be seen at the extreme
Reader Reviews
lefthand side when an ls -al command is issued in a Unix directory. For example:
Using Samba, 2nd Edition
-rwxr--r--
1 tom
users
Windows, on the other hand, has four principal bits that it uses with any file: read-only, system, hidden,
andPublisher:
archive.O'Reilly
You can view these bits by right-clicking the file and choosing the Properties menu item. You
should
see
a
dialog similar to Figure 8-1.[1]
Pub Date: February 2003
ISBN:
0-596-00256-4
[1]
The system
checkbox
will probably be grayed for your file. Don't worry about thatyou should still be able to see
when
box is checked and when it isn't.
Pages:the
556
Slots: 1
This file has been marked to be invisible to the user, unless the operating system is explicitly set to
show it.
Archive
This file has been touched since the last DOS backup was performed on it.
Note that there is no bit to specify that a file is executable. DOS and Windows NT filesystems identify
executable files by giving them the extensions .exe,.com,.cmd, or .bat.
of is
Contents
Consequently,Table
there
no use for any of the three Unix executable bits that are present on a file in a
Index
Samba disk share. DOS files, however, have their own attributes that need to be preserved when they
Reviewspermission bits of the file on the Unix sideif it is instructed to do so. Mapping
by reusing theReader
executable
Errata
these bits, however, has an unfortunate side effect: if a Windows user stores a file in a Samba share, and
Using
Samba,
2nd
Edition
you view
it on
Unix
with the ls -al command, some of the executable bits won't mean what you'd expect
them
to.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Three Samba options decide whether the bits are mapped: maparchive,mapsystem , and maphidden.
Publisher: O'Reilly
These
options map the archive, system, and hidden attributes to the owner, group, and world execute
February
2003
bitsPub
of Date:
the file,
respectively.
You can add these options to the [data] share, setting each of their values
ISBN: 0-596-00256-4
as follows:
Pages: 556
[data]Slots: 1
map archive = yes
map system = yes
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
map hidden = yes
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new
as a primary
domain
and domain
member server,change
its support
for the use of
After that,
try role
creating
a file in the
sharecontroller
under Unixsuch
as hello.javaand
the permissions
of
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
the file to 755. With these Samba options set, you should be able to check the permissionsaccessing
on the
shared
files
and
printers
from
Unix
clients.
Windows
side
and
see that
each
of the
three values has been checked in the Properties dialog box. What
about the read-only attribute? By default, Samba sets this whenever a file does not have the Unix owner
write permission bit set. In other words, you can set this bit by changing the permissions of the file to
555.
The default value of the maparchive option is yes, while the other two options have a default value of no.
This is because many programs do not work properly if the archive bit is not stored correctly for DOS and
Windows files. The system and hidden attributes, however, are not critical for a program's operation and
are left to the discretion of the administrator.
Figure 8-2 summarizes the Unix permission bits and illustrates how Samba maps those bits to DOS
attributes. Note that the group read/write and world read/write bits do not directly translate to a DOS
attribute, but they still retain their original Unix definitions on the Samba server.
Figure 8-2. How Samba and Unix view the permissions of a file
File and directory creation masks are similar to umasks you have probably encountered while working
with Unix systems. They are used to help define the permissions that will be assigned to a file or
directory at the time it is created. Samba's masks work differently in that the bits that can be set are set
in the creation mask, while in Unix umasks, the bits cannot be set are set in the umask. We think you will
find Samba's method to be much more intuitive. Once in a while you might need to convert between a
Unix umask and the equivalent Samba mask. It is simple: one is just the bitwise complement of the
other. For example, an octal umask of 0022 has the same effect as a Samba mask of 0755.
Unix umasks are set on a user-by-user basis, usually while executing the GUI's or command-line shell's
Table
of Contents
startup scripts.
When
users connect to a Samba share from a network client, these scripts are not
Index supplies the ability to set the creation masks for files and directories. By default, this
executed, so Samba
is done on a share-by-share
basis, although you can use the include parameter in the Samba
Reviews
configuration file
(asReviews
explained in Chapter 6) to assign masks on a user-by-user basis, thus matching
Reader
conventional Unix
Erratabehavior.
Using Samba, 2nd Edition
To show how Samba's create masks work, suppose we have a Windows Me user connecting to his Unix
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
home directory through Samba, and Samba is configured with createmask=777 in the [homes] share.
With this value, createmask will not affect the bits that are set on new files. If the user creates a file with
Publisher:itO'Reilly
Wordpad,
will appear in the Unix filesystem like this:
Pub Date: February 2003
$ls -lISBN:
file.doc
0-596-00256-4
Pages: 556
-rwxrw-rw-
Slots: 1
1 jay
jay
Wordpad created the file with read/write permissions (i.e., the MS-DOS read-only attribute was not set),
so Samba mapped the MS-DOS attributes to Unix read/write permissions for user, group, and other. The
execute bit is set for the owner because by default, the maparchive parameter is set to yes. The other
Using Samba,
Second
Edition
is amap
comprehensive
guide
to Samba
This
new
covers
execute
bits are
not set
because
system and map
hidden
are setadministration.
to no by default.
You
canedition
customize
all versions
ofas
Samba
from
2.2, including
selectedfrom
features
fromor
anWindows
alpha version
of 3.0,
well as
this
behavior
you see
fit,2.0
andtounless
you do backups
MS-DOS
systems,
youas
might
the SWAT
graphical
configuration
for
Windows
2000, ME,asand
XP, the book
alsoUnix
explores
want
to specify
maparchive
=no to tool.
avoidUpdated
Windows
files
from appearing
executables
on the
Samba's new role as a primary domain controller and domain member server, its support for the use of
system.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
Now
suppose
files and
weprinters
set create
from
mask
Unix
toclients.
have an effect. For example:
[homes]
create mask = 664
This is equivalent to a Unix umask of 113. If the user creates the Wordpad document as before, it will
show up as:
$ls -l file.doc
-rw-rw-r--
1 jay
jay
Comparing this to the previous example, notice that not only has the write permission for other
disappeared as we expected, but so has the execute permission for owner. This happened because the
value of createmask logically ANDs the owner's permissions with a 6, which has masked off the execute
bit. The lesson here is that if you want to enable any of maparchive,mapsystem, or maphidden, you
must be careful not to mask off the corresponding execute bit with your createmask.
Thedirectorymask option works similarly, masking permissions for newly created directories. The
following example will allow the permissions of a newly created directory to be, at most, 755:
[data]
directory mask = 755
Also, you can force various bits with the forcecreatemode and forcedirectorymode options. These
options will perform a logical OR against the file and directory creation masks, ensuring that those bits
that are specified will always be set. You would typically set these options globally to ensure that group
and world read/write permissions have been set appropriately for new files or directories in each share.
In the same spirit, if you wish to set explicitly the Unix user and group attributes of a file created on the
Windows side, you can use the forceuser and forcegroup options. For example:
[data]
create mask = 744
directory mask = 755
force user = joe
Table of Contents
force group
Index = accounting
Reviews
These optionsReader
assignReviews
the same Unix username and group to every client that connects to the share.
are frequently
used
for their side effects of assigning a specific user and group to each new file or
Using
Samba, 2nd
Edition
directory that is created in a share. Use these options with discretion.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Finally, one of the capabilities of Unix that DOS lacks is the ability to delete a read-only file from a
Publisher:
O'Reilly In Unix, if a directory is writable, a read-only file in that directory can still be removed.
writable
directory.
ThisPub
could
Date:permit
Februaryyou
2003to delete files in any of your directories, even if the file was left by someone else.
ISBN: 0-596-00256-4
DOS filesystems are not designed for multiple users, and so its designers decided that read-only means
Pages: 556
"protected against accidental change, including deletion," rather than "protected against some other user
Slots: 1
on a single-user machine." So the designers of DOS prohibited removal of a read-only file. Even today,
Windows filesystems exhibit the same behavior.
Normally, this is harmless. Windows programs don't try to remove read-only files because they know it's
Using
Second aEdition
is a
guideprogramswhich
to Samba administration.
new for
edition
covers
a
bad Samba,
idea. However,
number
ofcomprehensive
source-code control
were firstThis
written
Unixrun
all versions
on
Windowsof
and
Samba
require
from
the2.0
ability
to 2.2,
to delete
including
read-only
selected
files.
features
Samba
from
permits
an alpha
this behavior
version ofwith
3.0,the
as delete
well as
the SWAT option.
readonly
graphical
Toconfiguration
enable this functionality,
tool. Updated
setfor
the
Windows
option to
2000,
yes:ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
[data]
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
delete readonly = yes
Option
Parameters
Function
Default Scope
create mask(create
mode)
numeric
0744
Share
directory mask
(directory mode)
numeric
0744
Share
numeric
0000
Share
0000
Share
None
Share
None
Share
Boolean
no
Share
Boolean
yes
Share
Boolean
no
Share
Table of Contents
Index
Reviews
force directorymode
numeric
Reader Reviews
string ( group
force group(group)
Errata
Using Samba, 2nd Edition
name)
By
David Collier-Brown
, Robert string
Eckstein, Jay Ts
force
user
(username)
Publisher: O'Reilly
delete readonly
map archive
Pages: 556
Slots: 1
map system
When saving documents, many Windows applications rename their datafiles with a
.bak extension and create new ones. When the files are in a Samba share, this
changes their ownership and permissions so that members of the same Unix group
can't edit them. Setting forcecreate mode = 0660 will keep the new file editable
by members of the group.
Table of Contents
Index
This option sets the permission bits that Samba will set when a directory permission change is made or a
Reviews
directory is created. It's often used to force group permissions, as mentioned previously. This option
Reader Reviews
defaults to 0000
and can be used just like the forcecreatemode to add group or other permissions if
Errata
needed.
Using Samba, 2nd Edition
deleted, renamed, or moved without special effort. Set this option only if you need to store Windows
system files on the Unix fileserver. Executable Unix programs will appear to be nonremovable, special
Windows files when viewed from Windows clients. This might prove mildly inconvenient if you want to
move or remove one. For most sites, however, this is fairly harmless.
For map archive to work properly, the execute bit for group must not be masked off with the createmask
parameter.
of Contents
8.2.2.10 mapTable
hidden
Index
Reviews
DOS uses the hidden attribute to indicate that a file should not ordinarily be visible in directory listings.
Reader Reviews
Unix doesn't have such a facility; it's up to individual programs (notably, the shell) to decide what to
Errata
display and what
not to display. Normally, you won't have any DOS files that need to be hidden, so the
Using Samba, 2nd Edition
best thing to do is to leave this option turned off.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Setting this option to yes causes the server to map the hidden flag onto the executable-by-others bit
(0001).
This feature can produce a rather startling effect. Any Unix program that is executable by world
Publisher: O'Reilly
seems to vanish when you look for it from a Windows client. If this option is not set, however, and a
Pub Date: February 2003
Windows user attempts to mark a file hidden on a Samba share, it will not workSamba has no place to
ISBN: 0-596-00256-4
store the hidden attribute!
Pages: 556
For map
Slots:
archive
1
to work properly, the execute bit for other must not be masked off with the createmask
parameter.
Using Samba,
Second
Edition is a comprehensive guide to Samba administration. This new edition covers
8.2.2.11
inherit
permissions
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT
graphical
configuration
tool. is
Updated
for Windows
2000,
ME,
and XP,mask,
the book
also
explores
When
the inherit
permissions
option
set to yes,
the create
mask,
directory
force
create
Samba's
role
as a primary
controller
and domain
member
server,
support foron
thenewly
use of
mode,
andnew
force
directory
modedomain
are ignored.
The normal
behavior
of setting
theitspermissions
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
created files is overridden such that the new files and directories take on permissions from their parent
shared files
anddirectories
printers from
Unix clients.
directory.
New
will have
exactly the same permissions as the parent, and new files will inherit
the read and write bits from the parent directory, while the execute bits are determined as usual by the
values of the maparchive,maphidden, and mapsystem parameters.
By default, this option is set to no.
Table of
Contents
belongs, and everyone
else, respectively.
Index
Reviews
Windows
95/98/Me
has a file-protection system that is essentially no protection at all. This family of
Reader Reviews
operating systems was developed from MS-DOS, which was implemented as a non-networked, single
Errata
user system. Multiuser security simply was never added. One apparent exception to this is user-level
Using Samba, 2nd Edition
security for shared files, which we will discuss in Chapter 9. Here, separate access permissions can be
By
David Collier-Brown
, Robert
Eckstein
, Jay Ts
assigned
to individual
network
client
users or groups. However, user-level security on Windows 95/98/Me
systems requires a Windows NT/2000 or Samba server to perform the actual authentication.
Publisher: O'Reilly
On Windows
NT/2000/XP,
user-level security is an extension of the native file security model, which
Pub Date: February
2003
involves
access
control
lists
(ACLs). This system is somewhat more extensive than the Unix security
ISBN: 0-596-00256-4
model, allowing the access rights on individual files to be set separately for any number of individual
Pages: 556
users and/or any number of arbitrary groups of users. Figure 8-3,Figure 8-4, and Figure 8-5 show the
dialog Slots:
boxes1 on a Windows 2000 system in which the ACL is set for a file. By right-clicking a file's icon
and selecting Properties, then selecting the Security tab, we get to the dialog box shown in Figure 8-3.
Here, we can set the basic permissions for a file, which are similar to Unix permissions, although not
identical.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Figure 8-3. The Security tab of the file Properties dialog
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
By clicking the Advanced tab, we can bring up the dialog box shown in Figure 8-4, which shows the list of
access control entries (ACEs) in the ACL. In this dialog, ACEs can be added to or deleted from the ACL, or
an existing ACE can be viewed and modified. Each ACE either allows or denies a set of permissions for a
specific user or group.
Figure 8-4. The Permissions tab of the Access Control Settings dialog
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Figure 8-5 shows the dialog box for adding an ACE. As you can see, there are more options for
permissions in an ACL than with the permission bits on typical Unix systems. You can learn more about
these settings in Essential Windows NT System Administration, published by O'Reilly.
In a networked environment where a Samba server is serving files to Windows NT/2000/XP clients,
Samba has to map Unix permissions for files and directories to Windows NT/2000/XP access control lists.
When a Windows NT/2000/XP client accesses a shared file or directory on a Samba server, Samba
translates the object's ownership, group, and permissions into an ACL and returns them to the client.
Figure 8-6 shows the Properties dialog box for the file shopping_list.doc that resides on the Samba
server.
Figure 8-6. The Properties dialog for a file on the Samba server
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Figure 8-7. The Security tab of the Properties dialog for a file on the Samba
server
The owner of the file (adilia) is shown as one entry, while the group (users) and other permissions are
presented as the groups called users and Everyone. Clicking one of the items in the upper windows
causes the simplified view of the permissions in that item to appear in the bottom window. Here, the
read/write permissions for adilia appear in a manner that makes the security model of Unix and
Windows seem similar. However, clicking the Advanced . . . button brings up the additional dialog box
shown in Figure 8-8.
Figure 8-8. The Access Control Settings dialog for a file on the Samba server
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
In this dialog box, we see the actual ACL of the file. The ACEs for users and Everyone are listed with
Take Ownership in the Permission column. This is a trick used by Samba for ACLs that have no
permissions on the Unix side. On Windows, an ACL with nothing set results in no ACL at all, so Samba
Using
Samba,
Second Edition
is a comprehensive
to the
Samba
new
edition
covers
sets the
Take Ownership
permission
to make sureguide
that all
ACLsadministration.
corresponding This
to the
Unix
"user,
all versions
of permissions
Samba fromwill
2.0show
to 2.2,
selected
from an permission
alpha version
3.0, as well as
group,
other"
upincluding
on Windows.
The features
Take Ownership
hasofno
the SWAT graphical
configuration
tool.
Updated
for Windows
ME, and
thefile
book
explores
corresponding
Unix attribute,
so the
setting
on Windows
does2000,
not affect
the XP,
actual
on also
the Unix
system
Samba's
new
role as aWindows
primary client
domain
controller
andmisled
domain
member
server,
its support
for the use
of
in
any way.
Although
users
might be
into
thinking
they can
take ownership
of the
Windows
NT/2000/XP
filesystem
security on
host
Unix system,
and
file
(that is,
change theauthentication
ownership of and
the file
to themselves),
an the
actual
attempt
to do so
willaccessing
fail.
shared files and printers from Unix clients.
The Permissions column for the adilia ACL is listed as Special because Samba reports permissions for
the file that do not correspond to settings for which Windows has a more descriptive name. Clicking the
entry and then clicking the View/Edit . . . button brings up the dialog box shown in Figure 8-9, in which
the details of the ACL permissions can be viewed and perhaps modified.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
We say "perhaps" here because checking or unchecking boxes in this dialog box might not result in
settings that Samba is able to map back into the Unix security model. When a user attempts to modify a
Using
Edition
a comprehensive
administration.
This or
new
edition
settingSamba,
(either Second
permissions
or is
ownership)
that sheguide
does to
notSamba
have authority
to change,
does
not covers
all versions to
of Samba
from 2.0
2.2,
including
selected
fromwith
an alpha
version
ofor
3.0,
well as
correspond
a valid setting
onto
the
Unix
system,
Samba features
will respond
an error
dialog
by as
quietly
the SWAT
graphical
configuration
ignoring
the
unmappable
settings.tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
authentication
and filesystem
on the
and accessing
The
ACLs NT/2000/XP
for a directory
are slightly different.
Figuresecurity
8-10 shows
thehost
ACLUnix
viewsystem,
after clicking
the Advanced
shared files and printers from Unix clients.
button.
Figure 8-10. The Access Control Settings dialog for a directory on the Samba
server
Here, there are two ACLs each for users and Everyone. One ACL specifies the permissions for the
directory itself, and the other specifies permissions for the directory's contents. When changing settings
in the View/Edit... dialog, there is an extra drop-down menu to apply the settings either to just the
directory or to some combination of the directory and the files and directories it contains. If settings are
applied to more than just the directory, Samba will match the behavior of a Windows server and change
the permissions on the contents of the directory, as specified in the dialog.
Table of Contents
When the underlying
Unix host operating system supports POSIX.1e ACLs, Samba provides much better
support of Windows
Index NT/2000/XP ACLs. Versions of Unix that offer the necessary support include the
following:
Reviews
Reader Reviews
Errata
ByDavid
Collier-Brown
, Robert Eckstein, Jay Ts
SGI
Irix
Linux, O'Reilly
with Andreas
Publisher:
AIX
Slots: 1
FreeBSD 5.0 and later
HP/UX 11.0 and later, with the JFS 3.3 filesystem layout Version 4
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of Samba
from 2.0
to 2.2,
including
version
of 3.0,
as wellall
as
If you
are fortunate
enough
to have
a Unix
host selected
operatingfeatures
system from
with an
ACLalpha
support
already
provided,
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
you need to do is recompile Samba using the --with-acl-support configure option, as we described in
Samba's
new
role are
as arunning
primaryLinux
domain
and domain
member
server,
its support
the use of
Chapter 2.
If you
andcontroller
need to patch
your kernel,
things
are much
more for
complicated.
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
We suggest you refer to the documentation that comes with the patch for details on using it.
shared files and printers from Unix clients.
Parameters
Function
Default Scope
nt acl support
Boolean
yes
Share
security mask
numeric
0777
Share
force securitymode
numeric
0000
Share
directorysecurity
mask
numeric
0777
Share
force directory
security mode
numeric
0000
Share
This parameter defaults to yes, which allows users on Windows NT/2000/XP clients to modify ACL
settings for files on the Samba server. When set to no, files show up as owned by Everyone, with
permissions appearing as "Full Control". However, actual ownership and permissions are enforced as
whatever they are set to on the Samba server, and the user on the Windows client cannot view or modify
them with the dialog boxes used for managing ACLs.
When enabled, support for Windows NT/2000/XP ACLs is limited to whatever ownerships and permissions
can map into valid users and permissions on the Samba server. If the server supports ACLs (either "out
of the box" or with an additional patch to enhance the filesystem), Samba's ACL support more closely
of ContentsNT/2000/XP server.
matches that Table
of a Windows
Index
Reviews
8.3.2.2
Reader
Reviews
security
mask
Errata
Using
2nd Edition
UsingSamba,
the security
mask
option, it is possible to define which file permissions users can modify from
By
David Collier-Brown
, Robert
Eckstein
, Jay
Windows
NT/2000/XP
clients.
This
isTs
for files only and not directories, which are handled with the
directorysecuritymask option. The parameter is assigned a numeric value that is a Unix-style
permissions
mask. For bits in the mask that are set, the client can modify the corresponding bits in the
Publisher: O'Reilly
files'
permissions.
If the bit is zero, the client cannot modify that permission. For example, if security
Pub Date: February 2003
mask is set as:
ISBN: 0-596-00256-4
Pages: 556
[data]
Slots: 1
The default value of forcesecuritymode is 0000, which allows users to remove any permission from
files.
Table users
of Contents
Index
Reviews
8.3.2.5
forceReader
directory
security mode
Reviews
Errata
This option
exactly the same as the forcesecuritymode option, except that it operates on
Using
Samba,works
2nd Edition
directories
rather
than
files. It also has a default value of 0000, which allows Windows NT/2000/XP client
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
users to remove any permissions from directories in the share.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contentscase-sensitive, filenames. Table 8-4 shows the current naming state of
several popular
operating systems.
Index
Reviews
Reader Reviews
Errata
Operating
system
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
File-naming rules
Eight characters followed by a dot followed by a three-letter extension (8.3
format); case-insensitive
Windows 95/98/Me
Windows NT/2000/XP
255 characters; case-insensitive but case-preserving
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
Unix
versions of Samba from 255
2.0 to
characters;
2.2, including
case-sensitive
selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba'sstill
new
role
a primary
domain controller
andnetwork
domain clients
member
server,
support
of
Samba
has
to as
remain
backward-compatible
with
that
store its
files
in just for
thethe
8.3use
format,
Windows
NT/2000/XP
authentication
filesystem
the host
Unix system, and accessing
such
as Windows
for Workgroups.
If aand
user
creates asecurity
file on aon
share
called
shared files and printers from Unixa clients.
antidisestablishmentarianism.txt,
Windows for Workgroups client cannot tell it apart from another file in
the same directory called antidisease.txt. Like Windows 95/98/Me and Windows NT/2000/XP, Samba has
to employ a special method for translating a long filename to an 8.3 filename in such a way that similar
filenames will not cause collisions. This is called name mangling, and Samba deals with this in a manner
that is similar, but not identical to, Windows 95 and its successors.
virtuosity.dat
VIRTU~F1.DAT
.htaccess
HTACC~U0._ _ _
hello.java
HELLO~1F.JAV
team.config.txt
TEAMC~04.TXT
antidisestablishmentarianism.txt
ANTID~E3.TXT
Index
antidisease.txt
ANTID~9K.TXT
Table of Contents
Reviews
Reader
Using these rules
willReviews
allow Windows for Workgroups to differentiate the two files on behalf of the poor
Errata
individual who is forced to see the network through the eyes of that operating system. Note that the
Using
2nd Edition
same Samba,
long filename
should always hash to the same mangled name with Samba; this doesn't always
happen
with
Windows.
The
downside
of this approach is that there can still be collisions; however, the
ByDavid Collier-Brown, Robert
Eckstein
, Jay Ts
chances are greatly reduced.
O'Reilly
YouPublisher:
generally
want to use the mangling configuration options with only the oldest clients. We recommend
Pubthis
Date:without
February disrupting
2003
doing
other clients by adding an include directive to the smb.conf file:
ISBN: 0-596-00256-4
[global]
Pages: 556
Slots: 1
include = /usr/local/samba/lib/smb.conf.%a
This resolves to smb.conf.WfWg when a Windows for Workgroups client attaches. Now you can create a
file /usr/local/samba/lib/smb.conf.WfWg, which might contain these options:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
[global]
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
role as a=primary
domain controller and domain member server, its support for the use of
casenew
sensitive
no
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and
printers
from Unix clients.
default
case
= upper
preserve case = no
short preserve case = no
mangle case = yes
mangled names= yes
If you are not using Windows for Workgroups, you probably do not need to change any of these options
from their defaults.
Table of Contents
Index
Reader Reviews
8.4.2
Mangling
ReviewsOptions
Samba allows Errata
more refined instructions on how it should perform name mangling, including those
controlling
sensitivity, the character inserted to form a mangled name, and the ability to map
Using
Samba,the
2ndcase
Edition
filenames manually from one format to another. These options are shown in Table 8-5.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots:
1
Option
Parameters
Function
Default Scope
case sensitive
short preserve
case
Boolean
yes
Share
mangled names
Boolean
yes
Share
mangle case
Boolean
no
Share
mangling char
string (single
character)
Share
mangled stack
numeric
50
Global
mangled map
string (list of
patterns)
None
Share
Thedefaultcase option is used with preservecase. This specifies the default case (upper or lower)
Samba uses to create a file on one of its shares on behalf of a client. The default case is lower, which
means that newly created files will have lowercase names. If you need to, you can override this global
option by specifying the following:
[global]
default case = upper
Table of Contents
overridden in Reviews
a program. We recommend that you use the default value unless you are dealing with a
Reader Reviews
Errata
8.4.2.3
preserve case
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
ThisPublisher:
option O'Reilly
specifies whether a file created by Samba on behalf of the client is created with the case
provided by the client operating system or the case specified by the earlier defaultcase configuration
Pub Date: February 2003
option. The default value is yes, which uses the case provided by the client operating system. If it is set
ISBN: 0-596-00256-4
tono, the
value of the defaultcase option (upper or lower) is used.
Pages: 556
Note that
Slots:
this
1 option does not handle 8.3 file requests sent from the clientsee the upcoming short
preservecase option. You might want to set this option to yes, for example, if applications that create
files on the Samba server demand the file be all uppercase. If instead you want Samba to mimic the
behavior of a Windows NT filesystem, you can leave this option set to its default, yes.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
8.4.2.4
short
preserve
case tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
and filesystem
on the
Unix
system,
accessing
This option
specifies whether
an 8.3 filename
createdsecurity
by Samba
on host
behalf
of the
client and
is created
with the
shared files
printers
Unix clients.
default
case and
of the
client from
operating
system or the case specified by the defaultcase configuration
option. The default value is yes, which uses the case provided by the client operating system. You can let
Samba choose the case through the defaultcase option by setting it as follows:
[global]
short preserve case = no
If you want to force Samba to mimic the behavior of a Windows NT filesystem, you can leave this option
set to its default, yes.
[data]
mangle case = yes
We recommend that you leave this option alone unless you have a well-justified need to change it.
Table of Contents
Reader Reviews
[data]
Errata
This share-level option specifies the mangling character used when Samba mangles filenames into the
Index
8.3 format. The default character used is a tilde (~). You can reset it to whatever character you wish. For
Reviews
instance:
Using Samba, 2nd Edition
mangling
char
= # Eckstein,Jay Ts
ByDavid
Collier-Brown
, Robert
Publisher:
O'Reilly stack
8.4.2.8
mangled
Pub Date: February 2003
0-596-00256-4
SambaISBN:
maintains
a local stack of recently mangled 8.3 filenames; this stack can be used to reverse-map
mangled
filenames
back to their original state. This is often needed by applications that create and save a
Pages:
556
file, close
it,
and
need
to modify it later. The default number of long filename/mangled filename pairs
Slots: 1
stored on this stack is 50. However, if you want to cut down on the amount of processor time used to
mangle filenames, you can increase the size of the stack to whatever you wish, at the expense of
memory and slightly slower file access:
Using
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
[global]
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
tool. Updated for Windows 2000, ME, and XP, the book also explores
mangled
stack configuration
= 100
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
8.4.2.9
mangled
map from Unix clients.
shared files
and printers
If the default behavior of name mangling is not sufficient, you can give Samba further instructions on
how to behave using the mangledmap option. This option allows you to specify mapping patterns that can
be used in place of name mangling performed by Samba. For example:
[data]
mangled map =(*.database *.db) (*.class *.cls)
Here, Samba is instructed to search each encountered file for characters that match the first pattern
specified in the parenthesis and convert them to the modified second pattern in the parenthesis for
display on an 8.3 client. This is useful in the event that name mangling converts the filename incorrectly
or converts it to a format that the client cannot understand readily. Patterns are separated by
whitespaces.
Table process
of Contents
an error from Index
the operating system and will have to wait until the lock is released.
Reviews
Samba
supports
the standard DOS and NT filesystem (deny-mode) locking requestswhich allow only
Reader Reviews
one process to write to an entire file on a server at a given timeas well as byte-range locking. In
Errata
addition, Samba supports a locking mechanism known in the Windows NT world as opportunistic locking,
Using Samba, 2nd Edition
or oplock for short.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
8.5.1
Opportunistic Locking
Pub Date: February 2003
ISBN: 0-596-00256-4
Opportunistic locking allows a client to notify the Samba server that it will not only be the exclusive writer
Pages:
of a file,
but556
will also cache its changes to that file locally to speed up access by reducing network
Slots:
1 can result in a large performance gaintypically 30%while at the same time reserving
activity.
This
network bandwidth for other purposes.
Because exclusive access can be obtained using regular file locks, the value of opportunistic locks is not
so
much
to lock
the fileEdition
as it isistoa cache
it. In fact,guide
a better
name for
opportunisticThis
locking
becovers
Using
Samba,
Second
comprehensive
to Samba
administration.
newmight
edition
opportunistic
caching.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
When
Samba
knows
a file in
one ofcontroller
its sharesand
hasdomain
been oplocked
a client,
marks for
its version
Samba's
new role
as that
a primary
domain
memberby
server,
its it
support
the use as
of
having
an
opportunistic
lock
and
waits
for
the
client
to
complete
work
on
the
file,
at
which
point
it
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
expects
the and
clientprinters
to sendfrom
its changes
back to the Samba server for synchronization with the copy on the
shared files
Unix clients.
server.
If a second client requests access to that file before the first client has finished working on it, Samba
sends an oplock break request to the first client. This tells the client to stop caching its changes and
return the current state of the file to the server so that the interrupting client can use it as it sees fit. An
opportunistic lock, however, is not a replacement for a standard deny-mode lock. It is not unheard of for
the interrupting process to be granted an oplock break only to discover that the original process also has
a deny-mode lock on a file as well. Figure 8-11 illustrates this opportunistic locking process.
In most cases, the extra performance resulting from the use of oplocks is highly desirable. However,
allowing the client to cache data can be a big risk if either the client or network hardware are unreliable.
Suppose a client opens a file for writing, creating an oplock on it. When another client also tries to open
the file, an oplock break request is sent to the first client. If this request goes unfulfilled for any reason
and the second client starts writing to the file, the file can be easily corrupted as a result of the two
processes writing to it concurrently. Unfortunately, this scenario is very real. Uncoordinated behavior
such as this has been observed many times among Windows clients in SMB networks (with files served
by Windows NT/2000 or Samba). Typically, the affected files are database files, which multiple clients
open concurrently for writing.
Table
of Contents
A more concrete
example
of oplock failure occurs when database files are very large. If a client is allowed
Reviews
though it might need to update only one record. The situation goes from bad to worse
when another Reader
client Reviews
tries to open the oplocked file. The first client might need to write the entire file back
Errata the second client's file open request can succeed. This results in another huge delay
(for both
clients),
which in practice often results in a failed open due to a timeout on the second client,
Using
Samba,
2nd Edition
perhaps along with a message warning of possible database corruption!
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
If you are having problems of this variety, you can turn off oplocks for the affected files by using the veto
Publisher:
O'Reilly
oplock
files
parameter:
Pub Date: February 2003
[dbdata]
ISBN: 0-596-00256-4
Pages: 556
Use the value of the parameter (a list of filename-matching patterns separated by slash characters) to
match all the files in the share that might be a source of trouble. The syntax of this parameter is similar
to that of the vetofiles parameter.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all you
versions
from
2.0 to
from an
version
of 3.0, as well as
If
want of
to Samba
be really
careful
and2.2,
canincluding
live with selected
reduced features
performance,
youalpha
can turn
off oplocks
the SWAT graphical
configuration
Windows
2000, ME, and XP, the book also explores
altogether,
preventing
the oplock tool.
breakUpdated
problemfor
from
ever occurring:
Samba's new role as a primary domain controller and domain member server, its support for the use of
[global]
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
oplocks = no
This disables oplocks for all files in all shares served by the Samba server. If you wish to disable oplocks
in just a specific share, you can specify the oplocks=no parameter in just that share:
[database]
oplocks = no
This example allows other shares, which might have less sensitive data, to attain better performance,
while trading performance for better data integrity for files in the [database] share.
Table of Contents
Index
Reviews
8.5.3 Locks
and Oplocks Configuration Options
Reader Reviews
Errata
Samba's options for locks and oplocks are given in Table 8-6.
Using Samba, 2nd Edition
Publisher: O'Reilly
ISBN: 0-596-00256-4
Option
Pages: 556
Slots: 1
locking
Parameters
Boolean
Function
Ifyes, turns on byte-range locks.
Default
yes
Scope
Share
strict
Ifyes, denies access to an entire file
no
Boolean
Share
locking
if a byte-range lock exists in it.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
posix
Ifyes, maps oplocks to POSIX locks
yes
all versions of Samba
Boolean
from 2.0 to 2.2, including selected features from an alpha
version of 3.0, as Share
well as
locking
on the local system.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain If
controller
and
member
server, its support for the use of
yes, turns
ondomain
local caching
of files
oplocks
yes
Boolean
Share
Windows NT/2000/XP
authentication and
on the host Unix system, and accessing
onfilesystem
the client security
for this share.
shared files and printers from Unix clients.
kernel
Ifyes, indicates that the kernel
yes
Boolean
Global
oplocks
supports oplocks.
level2
oplocks
Boolean
fake oplocks
Boolean
Share
blocking
locks
Boolean
yes
Share
veto oplock
files
string (list of
filenames)
None
Share
lock
directory
As specified in
Samba makefile
Global
yes
Share
8.5.3.1 locking
Thelocking option can be used to tell Samba to engage or disengage server-side byte-range locks on
behalf of the client. Samba implements byte-range locks on the server side with normal Unix advisory
locks and consequently prevents other properly behaved Unix processes from overwriting a locked byte
range.
This option can be specified per share as follows:
[accounting]
locking = yes
If the locking option is set to yes, the requestor is delayed until the holder of either type of lock releases
it (or crashes). If, however, the option is set to no, no byte-range locks are kept for the files, although
requests to lock and unlock files will appear to succeed. The option is set to yes by default; however, you
can turn this option off if you have read-only media.
Table of
Contents
typically
not
needed
if
a
client
adheres to all the locking mechanisms in place. This option is set to no by
Index
default;
however,
you
can
reset
it per share as follows:
Reviews
[accounting]Reader Reviews
Errata
Usingstrict
Samba, 2nd
Edition =
locking
yes
If this option is set to yes, mandatory locks are enforced on any file with byte-range locks.
Publisher: O'Reilly
Pub Date: February 2003
8.5.3.3ISBN:
posix
locking
0-596-00256-4
Pages: 556
On systems
Slots: 1that support POSIX locking, Samba automatically maps oplocks to POSIX locks. This
behavior can be disabled by setting posixlocking=no. You should never need to change the default
behavior, which is posixlocking=yes.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
8.5.3.4
oplocks
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
This
option
enables
for oplocksand
on domain
the client.
The option
is enabled
by default.
Samba's
new
role asora disables
primary support
domain controller
member
server,
its support
for the use of
However,
you can disable
it with the following
command:
Windows NT/2000/XP
authentication
and filesystem
security on the host Unix system, and accessing
shared files and printers from Unix clients.
[data]
oplocks = no
If you are in an extremely unstable network environment or have many clients that cannot take
advantage of opportunistic locking, it might be better to shut this Samba feature off. If the host operating
system does not support kernel oplocks, oplocks should be disabled if users are accessing the same files
from both Unix applications (such as vi) and SMB clients.
Currently, Samba cannot support level 2 oplocks along with kernel oplocks and automatically disables
level 2 oplocks when kernel oplocks are in use. (This might change in future releases as improved
support for oplocks is added by the Samba developers.) If you are running Samba on a host system that
supports kernel oplocks, you must set kerneloplocks=no to enable support for level 2 oplocks.
Disabling oplocks with oplocks=no also disables level 2 oplocks.
Samba can automatically detect its Unix host's support of kernel oplocks and will set the value of kernel
oplocks automatically. You should never need to set this option in your Samba configuration file.
Table of Contents
Index
8.5.3.7
Reviews
fake oplocks
Reader Reviews
Errata
When this option
is set to yes, Samba pretends to allow oplocks rather than actually supporting them. If
Using
Samba,is2nd
Editionon
this option
enabled
a read-only share (such as a shared CD-ROM drive), all clients are told that the
files
areCollier-Brown
available for
opportunistic
and never warned of simultaneous access. As a result,
By
David
, Robert
Eckstein, Jaylocking
Ts
Windows clients cache more of the file's data and obtain much better performance.
Publisher: O'Reilly
This option was added to Samba before opportunistic-locking support was available, and it is now
Pub Date: February 2003
generally
considered better to use real oplocks. Do not ever enable fakeoplocks on a read/write share.
ISBN: 0-596-00256-4
Pages: 556
1
8.5.3.8Slots:
blocking
locks
Samba also supports blocking locks, a minor variant of range locks. Here, if the range of bytes is not
available, the client specifies an amount of time that it's willing to wait. The server then caches the lock
Using
Samba,
Secondchecking
Edition is
comprehensive
guide to Samba
administration.
This however,
new edition
covers
request,
periodically
toasee
if the file is available.
If it is, it
notifies the client;
if time
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as
well
as
expires, Samba will tell the client that the request has failed. This strategy prevents the client from
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
continually polling to see if the lock is available.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
filesystem security on the host Unix system, and accessing
You
can disable
this option
per share and
as follows:
shared files and printers from Unix clients.
[accounting]
blocking locks = no
When set to yes, blocking locks are enforced on the file. If this option is set to no, Samba behaves as if
normal locking mechanisms are in place on the file. The default is yes.
[global]
lock directory = /usr/local/samba/locks
You typically would not need to override this option, unless you want to move the lock files to a more
standard location, such as /var/spool/locks.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
Samba serverIndex
in real time. First, the value of the preexec parameter is set as follows:
Reviews
Reader Reviews
[global]
Errata
By
David
Collier-Brown
, Robert
Eckstein
, Jay
Ts and the connection to be written to the file /tmp/smblog
This
causes
information
about
the
user
whenever any client connects to any share. To watch clients connect, run the following command:
Publisher: O'Reilly
$tail -f /tmp/smblog
Pub Date: February 2003
ISBN: 0-596-00256-4
Table of Contents
Index
Reviews
8.6.1
Connection
Script Options
Reader Reviews
Errata
Table
8-7 introduces
some of the configuration options provided for setting up users.
Using Samba,
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Option
Slots: 1
root preexec
Parameters
string (Unix
command)
Function
Sets a Unix command to run as root, before
connecting to the share.
Default Scope
None
Share
root preexec
If set to yes, nonzero exit status of root
no
Boolean
Using
guide towill
Samba
administration. This new edition Share
covers
closeSamba, Second Edition is a comprehensive
preexec command
disconnect.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
string
(Unix
a Unix
run ME,
as the
user
the
SWAT(exec)
graphical
configuration
tool.Sets
Updated
forcommand
Windows to
2000,
and
XP,before
the bookNone
also explores
preexec
Share
command)
connecting
to
the
share.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and
filesystem
security exit
on the
hostofUnix
system, and accessing
If set
to yes, nonzero
status
preexec
preexec
close
no
Boolean
Share
shared
files
and printers
from Unix clients.
command will disconnect.
postexec
string (Unix
command)
None
Share
rootpostexec
string (Unix
command)
None
Share
8.6.1.3 preexec
Sometimes just called exec, this option defines an ordinary unprivileged command run by Samba as the
user specified by the variable %u. For example, a common use of this option is to perform logging, such
as the following:
[homes]
preexec = echo "%u connected from %m (%I)\" >>/tmp/.log
You
must redirect
standard output of the command if you want to use it. Otherwise, it is discarded.
Table the
of Contents
This
warning
also
applies
to the command's standard error output. If you intend to use a preexec script,
Index
you
should
ensure
that
it
will run correctly before having Samba invoke it.
Reviews
Reader Reviews
Errata
8.6.1.4
preexec
close
Using Samba,
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
This is similar to rootpreexecclose, except that it goes with the preexec option. By setting preexec
close=yes, a preexec script that returns nonzero will cause the share to disconnect immediately.
Publisher: O'Reilly
Table of
Contents
possible to organize
Index file shares on the network so that they appear to users as organized in a single
directory tree Reviews
on a single server, regardless of which servers on the network actually contain the
resources. Instead
having to browse the entire network, users can go to the Dfs share and locate their
Readerof
Reviews
data
much more
easily.
Errata
Using Samba, 2nd Edition
Dfs can also help administrators because it provides a level of indirection between the name of a shared
By
Davidand
Collier-Brown
, Robert
Eckstein
folder
its actual
location.
The,Jay
DfsTsshare contains references to resources on the network, and when a
resource is accessed, the Dfs server hands the client off to the actual server of the resource. When
moving
Publisher:
resources
O'Reilly to another computer, the reference to the resource in the Dfs share can be redirected
to the
in one step, with the change being entirely seamless for users.
Pub new
Date: location
February 2003
ISBN: 0-596-00256-4
To a limited extent, Dfs also can help improve performance for read-only shares because it provides load
Pages: 556
balancing. It is possible to set up a Dfs reference to point to identical shares on two or more servers. The
Slots: 1
Dfs server
then divides requests between the servers, dividing the client load among them. However, this
works well only for static, read-only data because no provision is included in Dfs for synchronization
among the servers when changes are made on any of them.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
8.7.1
Windows Dfs Clients
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Modern
of Windows
come with
extra
configuration
is required.
Windowsversions
NT/2000/XP
authentication
andclient-side
filesystemsupport
securityfor
onDfs,
the and
hostno
Unix
system,
and accessing
Support
is
more
limited
for
older
versions,
however.
Windows
for
Workgroups
cannot
function
as a Dfs
shared files and printers from Unix clients.
client at all. Windows NT 4.0 must be upgraded to at least Service Pack 3 to act as a Dfs client, and the
Dfs Client must be installed. Later service packs (such as Service Pack 6) include the Dfs Client. Windows
95 must also have the Dfs Client software installed to act as a Dfs client. Without the Dfs Client software,
double-clicking a remote folder in a Dfs share will show an empty folder, and no error message will
appear.
To use the Dfs Client for Windows 95 or Windows NT, you must first download and
install it. See the web page
http://microsoft.com/ntserver/nts/downloads/winfeatures/NTSDistrFile/default.asp
for a link to download the installation program and instructions on how to install
the Dfs Client.
This can be any directory, but it is important that it be owned by root and given the proper permissions:
#chown root:root /usr/local/samba/dfs
#chmod 755 /usr/local/samba/dfs
The Dfs directory tree can have subdirectories and files, just like any other shared directory. These will
function just as they would in any other share, allowing clients to access the directories and files on the
Samba
server.Table
Theofwhole
idea of Dfs, though, is to gather together shares on other servers by making
Contents
references to them in the Dfs tree. The way this is implemented with Samba involves a clever use of
Index
symbolic links, which can be in the Dfs root directory or any subdirectory in the Dfs tree.
Reviews
Reader
Reviews
You are probably
familiar
with using symbolic links to create references to files that exist on the same
Errata
system, and perhaps crossing a local filesystem boundary (which ordinary Unix links cannot do). But
Using
Samba,
2nd Edition
maybe
you didn't
know
that symbolic links have a more general functionality. Although we can't display
itsDavid
contents
directly,
as we
could,Jay
with
By
Collier-Brown
, Robert
Eckstein
Tsa text or binary file, a symbolic link "contains" an ASCII text string
naming what the link points to. For example, take a look at the listing for these symbolic links:
Publisher: O'Reilly
jay
Pages: 556
lrwxrwxrwx
Slots: 1
1 jay
jay
As you can infer from the size of the wrdlnk link (15 bytes), the string /usr/dict/words is encoded into
it. The size of alnk (9 bytes) is smaller, corresponding to the shorter name of dreamtime.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Now let's create a link in our Dfs root for an SMB share:
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
#cd SWAT
/usr/local/samba/dfs
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP authentication
and filesystem security on the host Unix system, and accessing
#ln -s 'msdfs:maya\e'
maya-e
shared files and printers from Unix clients.
#ls -l maya-e
lrwxrwxrwx
1 root
root
This link might appear as a "broken" link in a directory listing because it points to something that isn't a
file on the local system. For example, the file command will report:
$file maya-e
maya-e: broken symbolic link to msdfs:maya\e
However,maya-e is a valid reference to the \\maya\e share when used with Samba's Dfs support. When
Samba encounters this file, it sees the leading msdfs: and interprets the rest as the name of a remote
share. The client is then redirected to the remote share.
When creating links in the Dfs root directory, simply follow the same format, which in general is
msdfs:server\share. Note that this is similar to a UNC appended onto the msdfs: string, except that in
this case, the two backslashes preceding the server's name are omitted.
The names for the symbolic links in Dfs shares must be in all lowercase.
In addition to regular network shares, you can use symbolic links of this type to reference Dfs shares on
other Dfs servers. However, referencing printer shares does not work. Dfs is for sharing files only.
To set up a load-balancing Dfs share, create the symbolic link like this:
#ln -s 'msdfs:toltec\data,msdfs:mixtec\data' lb-data
That is, simply use a list of shares separated by commas as the reference. Remember, it is up to you to
make sure the shared folders remain identical. Set up permissions on the servers to make the shares
read-only to users.
The last thing we need to do is to modify the smb.conf file to define the Dfs root share and add Dfs
Table of Contents
support. The Dfs root is added as a share definition:
Index
[dfs]
Reviews
Reader Reviews
Errata
path = /usr/local/samba/dfs
msdfs
root =,Robert
yes Eckstein,Jay Ts
ByDavid
Collier-Brown
You can use any name you like for the share. The path is set to the Dfs root directory we just set up, and
O'Reilly
the Publisher:
parameter
msdfsroot=yes tells Samba that this share is a Dfs root.
Pub Date: February 2003
To enable
ISBN:support
0-596-00256-4
for Dfs in the server, we need to add one line to the [global] section:
Pages: 556
[global]
Slots: 1
host msdfs = yes
Restart the Samba daemonsor just wait a minute for them to reread the configuration fileand you will
Using
Samba,
Second
Edition
is a clients.
comprehensive
guide
to Samba
administration.
newshares
editionincovers
see the
new share
from
Windows
If you have
trouble
accessing
any of the This
remote
the
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as well as
Dfs share, recheck your symbolic links to make sure they were created correctly.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
If you previously had a share by the same name as your Dfs share, you might need
shared files and printers from Unix clients.
to reboot Windows clients before they can access the share as a Dfs share.
Table of Contents
Index
Errata
Samba
has the
ability to work with NIS and NIS+ to find the server on which the home directories
Reviews
actually
reside
so
that they can be shared directly from that server. For this to work, the server that
Reader Reviews
holds the home directories must also have Samba running, with a [homes] share of its own.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Table 8-8 introduces the NIS configuration options specifically for setting up users.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Table
of Contents
One of Samba's
most
complicated tasks lies in reconciling the security models of Unix and Windows
Index
systems. Samba must identify users by associating them with valid usernames and groups, authenticate
Reviews
them by checking
their passwords, then control their access to resources by comparing their access
Reader Reviews
rights to the permissions
on files and directories. These are complex topics on their own, and it doesn't
Errata
help that there
are three different operating system types to deal with (Unix, Windows 95/98/Me, and
Using Samba,
2nd Edition and that Samba supports multiple methods of handling user authentication.
Windows
NT/2000/XP)
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
For example: Index
Reviews
Reader Reviews
[dave]
Errata
path = /home/dave
ByDavid Collier-Brown
, Robert
Eckstein
, Jaydirectory
Ts
comment =
Dave's
home
writable
Publisher:
O'Reilly
= yes
valid
users =
ISBN:
0-596-00256-4
dave
Pages: 556
Thevalidusers option lists the users allowed to access the share. In this case, only the user dave is
1
allowedSlots:
to access
the share. In some situations it is possible to specify that any user can access a disk
share by using the guestok parameter. Because we don't wish to allow guest access, that option is
absent here. If you allow both authenticated users and guest users access to the same share, you can
make some files accessible to guest users by assigning world-readable permissions to those files while
Using Samba,
Second
Edition
a particular
comprehensive
to Samba administration. This new edition covers
restricting
access
to other
filesisto
users guide
or groups.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
When
client
graphical
users access
configuration
a Sambatool.
share,
Updated
they have
for Windows
to pass two
2000,
levels
ME,of
and
restriction.
XP, the book
Unix also
permissions
exploreson
Samba's
files
and directories
new role asapply
a primary
as usual,
domain
and controller
configuration
and parameters
domain member
specified
server,
in the
its Samba
supportconfiguration
for the use offile
Windows
apply
as well.
NT/2000/XP
In other authentication
words, a clientand
must
filesystem
first passsecurity
Samba's
onsecurity
the hostmechanisms
Unix system,
(e.g.,
and authenticating
accessing
with
a valid
and
password,
passing the check for the validusers parameter and the read
shared
files username
and printers
from
Unix clients.
only parameter, etc.), as well as the normal Unix file and directory permissions of its Unix-side user,
before it can gain read/write access to a share.
Remember that you can abbreviate the user's home directory by using the %H variable. In addition, you
can use the Unix username variable %u and/or the client username variable %U in your options as well. For
example :
[dave]
comment = %U home directory
writable = yes
valid users = dave
path = %H
With a single user accessing a home directory, access permissions are taken care of when the user
account is created. The home directory is owned by the user, and permissions on it are set appropriately.
However, if you're creating a shared directory for group access, you need to perform a few more steps.
Let's take a stab at a group share for the accounting department in the smb.conf file:
[accounting]
comment = Accounting Department Directory
writable = yes
valid users = @account
path = /home/samba/accounting
of Contents
Index
Errata
In
addition, you
need to create a shared directory that the members of the group can access and point to
Reviews
it with the path configuration option. Here are the Unix commands that create the shared directory for
Reader Reviews
the accounting department (assuming /home/samba already exists):
Using
Samba,
2nd Edition
#mkdir
/home/samba/accounting
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
#chmod
770 /home/samba/accounting
Pub Date: February 2003
ISBN: 0-596-00256-4
There are two other options in this smb.conf example, both of which we saw in the previous chapter.
556 are createmode and directorymode. These options set the maximum file and directory
ThesePages:
options
Slots: 1 that a new file or directory can have. In this case, we have denied all world access to the
permissions
contents of this share. (This is reinforced by the chmod command, shown earlier.)
Using
Second
Edition is Individual
a comprehensive
guide to Samba administration. This new edition covers
9.1.1Samba,
Handling
Multiple
Users
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Let's
return
torole
userasshares
for adomain
moment.
If we have
for whom
toits
set
up home
Samba's
new
a primary
controller
andseveral
domainusers
member
server,
support
for directory
the use of
shares, we probably want to use the special [homes] share that we introduced in Chapter 8. With the
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
[homes] share, all we need to say is:
shared files and printers from Unix clients.
[homes]
browsable = no
writable = yes
The[homes] share is a special section of the Samba configuration file. If a user attempts to connect to an
ordinary share that doesn't appear in the smb.conf file (such as specifying it with a UNC in Windows
Explorer), Samba will search for a [homes] share. If one exists, the incoming share name is assumed to
be a username and is queried as such in the password database ( /etc/passwd or equivalent) file of the
Samba server. If it appears, Samba assumes the client is a Unix user trying to connect to his home
directory.
As an illustration, let's assume that sofia is attempting to connect to a share called [sofia] on the
Samba server. There is no share by that name in the configuration file, but a [homes] share exists and
user sofia is present in the password database, so Samba takes the following steps:
1. Samba creates a new disk share called [sofia] with the path specified in the [homes] section. If no
path option is specified in [homes], Samba initializes it to her home directory.
2. Samba initializes the new share's options from the defaults in [globals], as well as any overriding
options in [homes] with the exception of browsable.
3. Samba connects sofia's client to that share.
The[homes] share is a fast, painless way to create shares for your user community without having to
duplicate the information from the password database file in the smb.conf file. It does have some
peculiarities, however, that we need to point out:
The[homes] section can represent any account on the machine, which isn't always desirable. For
example, it can potentially create a share for root,bin,sys,uucp, and the like. You can set a global
invalidusers option to protect against this.
The meaning of the browsable configuration option is different from other shares; it indicates only
that a [homes] section won't show up in the local browse list, not that the [alice] share won't.
When the [alice] section is created (after the initial connection), it will use the browsable value
from the [globals] section for that share, not the value from [homes].
As we mentioned,
is no need for a path statement in [homes] if the users have Unix home
Table there
of Contents
directories in the
server's /etc/passwd file. You should ensure that a valid home directory does exist,
Index
however, as Samba
Reviewswill not automatically create a home directory for a user and will refuse a tree
connect if the Reader
user's Reviews
directory does not exist or is not accessible.
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
We've
seen what
happens when you specify valid users. However, you are also allowed to specify a list of
Index
invalid
usersusers
Reviewswho should never be allowed access to Samba or its shares. This is done with the
invalidusers option. We hinted at one frequent use of this option earlier: a global default with the
Reader Reviews
[homes] section to ensure that various system users and superusers cannot be forged for access. For
Errata
example:
Using Samba, 2nd Edition
invalid
users
Publisher:
O'Reilly
Pages: 556
[homes]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
browsable
= no from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role
as a primary domain controller and domain member server, its support for the use of
writable
= yes
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
The
invalid
option,from
like valid
users, can take group names, preceded by an at sign (@), as well
shared
files users
and printers
Unix clients.
as usernames. In the event that a user or group appears in both lists, the invalidusers option takes
precedence, and the user or group is denied access to the share.
At the other end of the spectrum, you can explicitly specify users who will be allowed superuser (root)
access to a share with the adminusers option. An example follows:
[sales]
path = /home/sales
comment = Sedona Real Estate Sales Data
writable = yes
valid users = sofie shelby adilia
admin users = mike
This option takes both group names and usernames. In addition, you can specify NIS netgroups by
preceding them with an @ as well; if the netgroup is not found, Samba will assume that you are referring
to a standard Unix group.
Be careful if you assign administrative privileges to a share for an entire group. The Samba Team highly
recommends you avoid using this option, as it essentially gives root access to the specified users or
groups for that share.
If you wish to force read-only or read/write access on users who access a share, you can do so with the
readlist and writelist options, respectively. These options can be used on a per-share basis to
restrict a writable share or to grant write access to specific users in a read-only share, respectively. For
example:
[sales]
path = /home/sales
comment = Sedona Real Estate Sales Data
read only = yes
write list = sofie shelby
Table of Contents
ThewritelistIndex
option cannot override Unix permissions. If you've created the share without giving the
write-list user
write permission on the Unix system, she will be denied write access regardless of the
Reviews
setting of write
list.
Reader
Reviews
Errata
As mentioned
earlier, you can configure a share using guestok=yes to allow access to guest users. This
Publisher: O'Reilly
works
only
when
using
Pub Date: February
2003 share-level security, which we will cover later in this chapter. When a user
connects
as
a
guest,
authenticating with a username and password is unnecessary, but Samba still needs
ISBN: 0-596-00256-4
a way to map the connected client to a user on the local system. The guestaccount parameter can be
Pages: 556
used in the share to specify the Unix account that guest users should be assigned when connecting to the
Slots: 1
Samba server. The default value for this is set during compilation and is typically nobody, which works
well with most Unix versions. However, on some systems the nobody account is not allowed to access
some services (e.g., printing), and you might need to set the guest user to ftp or some other account
instead.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all you
versions
of restrict
Samba access
from 2.0
2.2, including
selected features
from an
ofas
3.0,
well as
If
wish to
in to
a share
only to guestsin
other words,
all alpha
clientsversion
connect
theas
guest
the SWAT
graphical
configuration
tool. Updated
2000,
ME,inand
XP, the book
explores
account
when
accessing
the shareyou
can usefor
theWindows
guestonly
option
conjunction
withalso
the guest
ok
Samba'sasnew
rolein
asthe
a primary
domain
controller and domain member server, its support for the use of
option,
shown
following
example:
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
[sales]
shared files and printers from Unix clients.
path = /home/sales
comment = Sedona Real Estate Sales Data
writable = yes
guest ok = yes
guest account = ftp
guest only = yes
Make sure you specify yes for both guestonly and guestok; otherwise, Samba will not use the guest
account that you specify.
Option
Parameters
Function
Default Scope
admin users
string (list of
usernames)
None
Share
valid users
string (list of
usernames)
None
Share
invalid users
string (list of
usernames)
None
Share
string (list of
usernames)
None
Share
None
Share
Share
no
Share
nobody
Share
Table of Contents
Index
Reviews
read list
Reader Reviews
string (list of
write list Errata
Using Samba, 2nd Edition
usernames)
By
David
Collier-Brown, Robert
Eckstein, Jay Ts
max
connections
numeric
Publisher:
O'Reilly
guest
only
(only
Boolean
guest)
Pub Date: February 2003
ISBN: 0-596-00256-4
guest
account
Pages:
556
string (name of
account)
Slots: 1
only access to a writable share and read/write access to a read-only share, respectively. The value of
either options is a list of users. The readlist parameter overrides any other Samba permissions
grantedas well as Unix file permissions on the server systemto deny users write access. Thewrite
list parameter overrides other Samba permissions to grant write access, but cannot grant write access
if the user lacks write permissions for the file on the Unix system. You can specify NIS or Unix group
names by prefixing the name with an at sign (such as @users). Neither configuration option has a default
value associated with it.
Table of Contents
9.2.2.4 max connections
Index
Reviews
This option specifies the maximum number of client connections that a share can have at any given time.
Reader Reviews
Any connections that are attempted after the maximum is reached will be rejected. The default value is 0,
Errata
which is a special case that allows an unlimited number of connections. You can override it per share as
Using Samba, 2nd Edition
follows:
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
[accounting]
Publisher: O'Reilly
max connections = 30
ISBN: 0-596-00256-4
This option is useful in the event that you need to limit the number of users who are accessing a licensed
Pages:
program
or 556
piece of data concurrently.
Slots: 1
This option specifies the name of the account to be used for guest access to shares in Samba. The default
for this option varies from system to system, but it is often set to nobody. Some default user accounts
have trouble connecting as guest users. If that occurs on your system, the Samba Team recommends
using the ftp account as the guest user.
Parameters
Function
Default Scope
usernamemap
string
(filename)
None
Global
username
level
numeric
Global
Unix network often cannot be longer than eight characters. This means that an individual user can have
one username on a client and another (shorter) one on the Samba server. You can get past this issue by
mapping a free-form client username to a Unix username of eight or fewer characters. It is placed in a
standard text file, using a format that we'll describe shortly. You can then specify the pathname to
Samba with the global usernamemap option. Be sure to restrict access to this file; make the root user the
file's owner and deny write access to others (with octal permissions of 744 or 644). Otherwise, an
untrusted user with access to the file can easily map his client username to the root user of the Samba
server.
Table
Contents
You
can specify
thisofoption
as follows:
Index
[global]
Reviews
Reader Reviews
usernameErrata
map = /usr/local/samba/private/usermap.txt
Each entry in the username map file should be listed as follows: the Unix username, followed by an equal
By
David
Collier-Brown
, Robert
Eckstein
Ts
sign
(=),
followed by
one or
more,Jay
whitespace-separated
SMB client usernames. Note that unless
instructed otherwise (i.e., a guest connection), Samba will expect both the client and the server user to
have
Publisher:
the same
O'Reilly
password. You can also map NT groups to one or more specific Unix groups using the @
sign.
Here
some
examples:
Pub
Date:are
February
2003
ISBN: 0-596-00256-4
jarwin = JosephArwin
Pages: 556
Slots: 1
manderso
= MarkAnderson
users = @account
Using
Samba,
Second
Edition to
is a
comprehensive
to Samba
administration.
This
new edition
covers
You
can
also use
the asterisk
specify
a wildcardguide
that matches
any
free-form client
username
as an
all versions
Samba from
entry
in the of
username
map 2.0
file:to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
nobody
* role as a primary domain controller and domain member server, its support for the use of
Samba's=new
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Comments
placedfrom
in the
file clients.
by starting the line with a hash mark (#) or a semicolon (;).
shared filescan
andbe
printers
Unix
Note that you can also use this file to redirect one Unix user to another user. Be careful, though, as
Samba and your client might not notify the user that the mapping has been made and Samba might be
expecting a different password.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
network:share,
user,server, and domain.
Index
Reviews
Errata
Share-level
security
Reader Reviews
Each share in the workgroup has one or more passwords associated with it. Anyone who knows a
valid password for the share can access it.
By
David Collier-Brown
User-level
security ,Robert Eckstein,Jay Ts
Using Samba, 2nd Edition
Each share
Publisher:
O'Reilly
in the workgroup is configured to allow access from certain users. With each initial tree
connection,
the Samba server verifies users and their passwords to allow them access to the share.
Pub Date: February 2003
Server-level security
ISBN: 0-596-00256-4
Pages:
This is556
the
same as user-level security, except that the Samba server uses another server to
Slots: 1 users and their passwords before granting access to the share.
validate
Domain-level security
Samba becomes a member of a Windows NT domain and uses one of the domain's domain
the PDC
a BDCto perform
Once authenticated,
the user
is
Using controllerseither
Samba, Second Edition
is a or
comprehensive
guide authentication.
to Samba administration.
This new edition
covers
given
a
special
token
that
allows
her
access
to
any
share
with
appropriate
access
rights.
With
this
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
token,
the domain
controllertool.
will not
have for
to revalidate
the user's
password
each
time
she
attempts
the SWAT
graphical
configuration
Updated
Windows 2000,
ME, and
XP, the
book
also
explores
to
access
another
share
within
the
domain.
The
domain
controller
can
be
a
Windows
NT/2000
Samba's new role as a primary domain controller and domain member server, its support for the usePDC
of
or BDC,
or Samba
acting as a Windows
NT PDC.
Windows
NT/2000/XP
authentication
and filesystem
security on the host Unix system, and accessing
shared files and printers from Unix clients.
Each security policy can be implemented with the global security option, as shown in Table 9-3.
Parameters
domain,server,share, or
user
Function
Indicates the type of security that the Samba
server will use
Default Scope
user
Global
Table of Contents
Index
Reviews
Reader Reviews
Errata
Next,
right-click a resourcesuch as a hard drive or a CD-ROMand select the Properties menu item.
Publisher: O'Reilly
This will bring up the Resource Properties dialog box. Select the Sharing tab at the top of the dialog box,
Pub Date: February 2003
and enable the resource as Shared As. From here, you can configure how the shared resource will appear
ISBN: 0-596-00256-4
to individual
users, as well as assign whether the resource will appear as read-only, read/write, or a mix,
Pages:
556the password that is supplied.
depending on
Slots: 1
You might be thinking that this security model is not a good fit for Sambaand you would be right. In
fact, if you set the security=share option in the Samba configuration file, Samba will still reuse the
username/password combinations in the system password files to authenticate access. More precisely,
Samba
will take
the following
steps
when a client requests
a connection
using share-level
Using Samba,
Second
Edition is
a comprehensive
guide to Samba
administration.
This newsecurity:
edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
1. When a connection is requested, Samba will accept the password and (if sent) the username of the
Samba's new role as a primary domain controller and domain member server, its support for the use of
client.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
and printers
2. If files
the share
is guestfrom
onlyUnix
, theclients.
user is immediately granted access to the share with the rights of
the user specified by the guestaccount parameter; no password checking is performed.
3. For other shares, Samba appends the username to a list of users who are allowed access to the
share. It then attempts to validate the password given in association with that username. If
successful, Samba grants the user access to the share with the rights assigned to that user. The
user will not need to authenticate again unless a revalidate=yes option has been set inside the
share.
4. If the authentication is unsuccessful, Samba attempts to validate the password against the list of
users previously compiled during attempted connections, as well as those specified under the share
in the configuration file. If the password matches that of any username (as specified in the system
password file, typically /etc/passwd ), the user is granted access to the share under that username.
5. However, if the share has a guestok or public option set, the user will default to access with the
rights of the user specified by the guestaccount option.
You can indicate in the configuration file which users should be initially placed on the share-level security
user list by using the username configuration option, as shown here:
[global]
security = share
[accounting1]
path = /home/samba/accounting1
guest ok = no
writable = yes
username = davecb, pkelly, andyo
Here, when a user attempts to connect to a share, Samba verifies the sent password against each user in
its own list, in addition to the passwords of users davecb,pkelly, and andyo. If any of the passwords
match, the connection is verified, and the user is allowed. Otherwise, connection to the specific share will
fail.
Table of Contents
Index
9.3.2
Share-Level
Security Options
Reviews
Reader Reviews
Errata
Table 9-4 shows the options typically associated with share-level security.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN:
0-596-00256-4
Option
Parameters
Pages: 556
only Slots:
user1
Boolean
Function
Ifyes, usernames specified by username
are the only ones allowed
Default Scope
no
Share
9.3.2.2 username
This option presents a list of usernames and/or group names against which Samba tests a connection
password to allow access. It is typically used with clients that have share-level security to allow
connections to a particular service based solely on a qualifying passwordin this case, one that matches
a password set up for a specific user:
[global]
security = share
[data]
username = andy, peter, terry
You can enter a list of usernames and/or group names. If a name is prefixed by an at sign (@), it is
interpreted as a group name, with NIS groups searched before Unix groups. If the name is prefixed by a
plus sign (+), it is interpreted as the name of a Unix group, and NIS is not searched. If the name is
prefixed by an ampersand (&), it is interpreted as an NIS group name rather than a Unix group name.
The plus sign and ampersand can be used together to specify whether NIS or Unix groups are searched
first. When Samba encounters a group name in this option, it attempts to authenticate each user in the
group until if finds one that succeeds. Beware that this can be very inefficient.
We recommend against using this option unless you are implementing a Samba server with share-level
security.
Table of Contents
9.3.3
User-Level
Security
Index
Reviews
The
default mode
of security with Samba is user-level security. With this method, each share is assigned
Reader Reviews
specific users that can access it. When a user requests a connection to a share, Samba authenticates by
Errata
validating the given username and password with the authorized users in the configuration file and the
Using Samba, 2nd Edition
passwords in the password database of the Samba server. As mentioned earlier in the chapter, one way
By
Collier-Brown
, Robert
, Jay
Ts
toDavid
isolate
which users
are Eckstein
allowed
access
to a specific share is by using the validusers option for each
share:
Publisher: O'Reilly
[global]
Pub Date: February
2003
ISBN: 0-596-00256-4
security = user
Pages: 556
Slots: 1
[accounting1]
Usingwritable
Samba, Second
= yes Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
tool. Updated for Windows 2000, ME, and XP, the book also explores
validgraphical
users = configuration
bob, joe, sandy
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
Each
userNT/2000/XP
listed can connect
authentication
to the share
and filesystem
if the password
security
provided
on thematches
host Unix
the
system,
password
and stored
accessing
in the
shared files
system
password
and printers
database
from
onUnix
the server.
clients.Once the initial authentication succeeds, the client will not need
to supply a password again to access that share unless the revalidate=yes option has been set.
Passwords can be sent to the Samba server in either an encrypted or a nonencrypted format. If you have
both types of systems on your network, you should ensure that the passwords represented by each user
are stored both in a traditional account database and Samba's encrypted password database. This way,
authorized users can gain access to their shares from any type of client.[1] However, we recommend that
you move your system to encrypted passwords and abandon nonencrypted passwords if security is an
issue.Section 9.4 of this chapter explains how to use encrypted as well as nonencrypted passwords.
[1]
Having both encrypted and nonencrypted password clients on your network is one of the reasons why Samba allows
you to include (or not include) various options in the Samba configuration file based on the client operating system or
machine name variables.
Table of Contents
IndexSamba to use a separate password server under server-level security with the use of
thepasswordserver
Reader Reviews
Errata
[global]
security = server
Note
that
you
can specify
more than one machine as the target of the passwordserver; Samba moves
Pub
Date:
February
2003
down the
list
of
servers
in
the event that its first choice is unreachable. The servers identified by the
ISBN: 0-596-00256-4
passwordserver option are given as NetBIOS names, not their DNS names or equivalent IP addresses.
Pages: 556
Also, if any of the servers reject the given password, the connection automatically failsSamba will not
Slots: 1
attempt another server.
One caveat: when using this option, you still need an account representing that user on the regular
Samba server. This is because the Unix operating system needs a username to perform various I/O
Using Samba,
Second
Edition
is a comprehensive
Samba
administration.
This
new
edition
covers
operations.
The
preferable
method
of handling thisguide
is to to
give
the user
an account on
the
Samba
server
all versions
of Samba
from
2.0 to 2.2,
featurespassword
from an alpha
version
of 3.0, as
well as
but
disable the
account's
password
by including
replacing selected
it in the system
file (e.g.,
/etc/passwd
) with
theasterisk
SWAT graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
an
(*).
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
With domain-level security, the Samba server acts as a member of a Windows domain. Recall from
Chapter 1 that each domain has a primary domain controller, which can be a Windows NT/2000 or
Samba server offering password authentication. The domain controller keeps track of users and
passwords in its own database and authenticates each user when she first logs on and wishes to access
another machine's shares.
As mentioned earlier in this chapter, Samba has a similar ability to offer user-level security, but that
option is Unix-centric and assumes that the authentication occurs via Unix password files. If the Unix
machine is part of an NIS or NIS+ domain, Samba authenticates users transparently against a shared
password file in typical Unix fashion. Samba then provides access to the NIS or NIS+ domain from
Windows. There is, of course, no relationship between the NIS concept of a domain and a Windows NT
domain.
Configuring Samba for domain-level security is covered in Chapter 4 in Section 4.7.
9.4 Passwords
Passwords are a thorny issue with Samba. So much so, in fact, that they are often the first major
problem that users encounter when they install Samba. At this point, we need to delve deeper into
Samba to discover what is happening on the network.
Table of Contents
Passwords
sent
from individual clients can be either encrypted or nonencrypted. Encrypted passwords
Index
are,
of
course,
more
Reviews secure. A nonencrypted, plain-text password can be easily read with a packetsniffing
program,
such as the modified tcpdump program for Samba that we used in Chapter 1. Whether
Reader Reviews
passwords are encrypted by default depends on the operating system that the client is using to connect
Errata
to the Samba server. Table 9-5 lists which Windows operating systems encrypt their passwords and
Using Samba, 2nd Edition
which send plain-text passwords by default.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Operating system
Windows 95
Plain text
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Windows
SMBfrom
Update
Encrypted
all
versions95
ofwith
Samba
2.0 to 2.2, including selected features
from an alpha version of 3.0, as well as
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
Windows 98
EncryptedME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
WindowsNT/2000/XP
Me
Encrypted
Windows
authentication and filesystem security
on the host Unix system, and accessing
shared files and printers from Unix clients.
Windows NT 3.x
Plain text
Windows NT 4.0 before SP 3
Plain text
Encrypted
Windows 2000
Encrypted
Windows XP
Encrypted
Three different encryption methods are used. Windows 95/98/Me clients use a method inherited from
Microsoft's LAN Manager network software. Windows NT/2000/XP systems use a newer system, called NT
LAN Manager, or NTLM. A newer version of this (called NT LAN Manager Version 2, or NTLMv2) uses a
different method for password hashing.
If encrypted passwords are supported, Samba stores the encrypted passwords in a file called
smbpasswd. By default, this file is located in the private directory of the Samba distribution (typically
/usr/local/samba/private). At the same time, the client stores an encrypted version of a user's password
on its own system. The plain-text password is never stored on either system. Each system encrypts the
password automatically using a standard algorithm when the password is set or changed.
When a client requests a connection to an SMB server that supports encrypted passwords (such as
Samba or Windows NT/2000/XP), the two computers undergo the following negotiations:
1. The client attempts to negotiate a protocol with the server.
2. The server responds with a protocol and indicates that it supports encrypted passwords. At this
time, it sends back a randomly generated 8-byte challenge string.
3. The client uses the challenge string as a key to encrypt its already encrypted password using an
algorithm predefined by the negotiated protocol. It then sends the result to the server.
4.
4. The server does the same thing with the encrypted password stored in its database. If the results
match, the passwords are equivalent, and the user is authenticated.
Note that even though the original passwords are not involved in the authentication process, you need to
be very careful that the encrypted passwords located inside the smbpasswd file are guarded from
unauthorized users. If they are compromised, an unauthorized user can break into the system by
replaying the steps of the previous algorithm. The encrypted passwords are just as sensitive as the plaintext passwordsthis is known as plain-text-equivalent data in the cryptography world. Of course, your
local security policy should require that the clients safeguard their plain-text-equivalent passwords as
Table of Contents
well.
Index
Reviews
Note that we explicitly
name the location of the Samba password file:
Reader Reviews
[global]
Errata
= yes
smb
passwd
file = /usr/local/samba/private/smbpasswd
ISBN:
0-596-00256-4
Pages: 556
Samba, however, will not accept any users until the smbpasswd file has been created and the users have
Slots: 1
been added to it with the smbpasswd command, as we showed you in Chapter 2.
9.4.1
Disabling
Passwordsguide
on the
Client
Using Samba,
SecondEncrypted
Edition is a comprehensive
to Samba
administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
While
Unixgraphical
authentication
has been
in use
for decadesincluding
the
use
of telnet
rlogin
the SWAT
configuration
tool.
Updated
for Windows 2000,
ME,
and
XP, theand
book
alsoaccess
explores
across
the
Internetit
embodies
well-known
security
risks.
Plaintext
passwords
are
sent
over
the use of
Samba's new role as a primary domain controller and domain member server, its support for the
Internet
can be retrieved
from TCP
by malicious
snoopers.
if youand
feelaccessing
that your
Windowsand
NT/2000/XP
authentication
andpackets
filesystem
security on
the hostHowever,
Unix system,
network
is
secure
and
you
wish
to
use
standard
Unix
/etc/passwd
authentication
for
all
clients,
you can
shared files and printers from Unix clients.
do so, but you must disable encrypted passwords on those Windows clients that default to using them.
To do this, you must modify the Windows registry on each client system. The Samba distribution includes
the.reg files you need for this, located in the source distribution's /docs/Registry directory. Depending on
the platform, you use one of the following files:
Win95_PlainPassword.reg
Win98_PlainPassword.reg
WinME_PlainPassword.reg
NT_PlainPassword.reg
Win2000_PlainPassword.reg
(For Windows XP, use the .reg file for Windows 2000.) You can perform the installation by copying the
appropriate.reg file to a DOS floppy, inserting the floppy in the client's floppy drive, and running the .reg
file from the Run menu item in the client's Start menu. (Or you can just double-click the file's icon.)
After you reboot the machine, the client will not encrypt its hashed passwords before sending them to the
server. This means that the plain-text passwords can been seen in the TCP packets that are broadcast
across the network. Again, we encourage you not to do this unless you are absolutely sure that your
network is secure.
If passwords are not encrypted, use these two lines in your Samba configuration file:
[global]
security = user
encrypt passwords = no
Samba stores its encrypted passwords in a file called smbpasswd, which by default resides in the
/usr/local/samba/private directory. The smbpasswd file should be guarded as closely as the Unix
system's password file (either /etc/passwd or /etc/shadow). Only the root user should have read/write
access to the private directory, and no other users should have access to it at all. In addition, the
smbpasswd file should have all access denied to all users except for root. When things are set up for
good security, long listings of the private directory and smbpasswd file look like the following:
#ls -ld /usr/local/samba/private
drwx- - - - Table
- - of Contents
2 root
Index
root
Reviews
#ls -l /usr/local/samba/private/smbpasswd
Reader Reviews
-rw- - - -Errata
- -
1 root
root
Before
you can use encrypted passwords, you need to create an entry for each Unix user in the
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
smbpasswd file. The structure of the file is somewhat similar to a Unix passwd file, but has different
fields.Figure 9-3 illustrates the layout of the smbpasswd file; the entry shown is actually one line in the
file.Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Figure
9-3. Structure of the smbpasswd file entry (actually one line)
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Normally, entries in the smbpasswd file are created automatically by the smbpasswd command. Still, you
might like to know how to interpret data within the smbpasswd file, in case you'd like to see what
accounts are stored in it or even modify it manually. Here is a breakdown of the individual fields:
Username
This is the username of the account. It is taken directly from the system password file.
UID
This is the user ID (UID) of the account. Like the username, it is taken directly from the system
password file and must match the UID there.
LAN Manager Password Hash
This is a 32-bit hexadecimal sequence that represents the password Windows 95/98/Me clients will
use. It is derived by splitting the password into two 7-character strings, with all lowercase letters
forced into uppercase. If fewer than 14 characters are in the password, the strings are padded with
nulls. Then each 7-character string is converted to a 56-bit DES key and used to encrypt the
constant string KGS!@#$%. The two 64-bit results are concatenated and stored as the password
hash.
If there is currently no password for the user, the first 11 characters of the hash will consist of the
sequenceNOPASSWORD followed by X characters for the remainder. If the password has been
disabled, it will consist of 32 X characters.
NT LAN Manager (NTLM) Password Hash
This is a 32-bit hexadecimal sequence that represents the password Windows NT/2000/XP clients
will use. It is derived by hashing the user's password (represented as a 16-bit little-endian Unicode
sequence) with an MD4 hash. The password is not converted to uppercase letters first.
Account Flags
This field consists of 11 characters between two braces ( [ ] ). Any of the following characters can
Table of Contents
This
account has no password associated with it.
Index
Reviews
Reader Reviews
This is a workstation trust account that can be used to configure Samba as a PDC when
Errata
allowing
Windows NT machines to join its domain.
Using Samba, 2nd Edition
Last Change Time
This code consists of the characters LCT- followed by a hexadecimal representation of the number
of seconds since the epoch (midnight on January 1, 1970) that the entry was last changed.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
9.4.3Pages:
Password
Synchronization
556
Slots: 1
Having a regular password (either in /etc/passwd or /etc/shadow) and an encrypted version of the same
password (in the smbpasswd file) can be troublesome when you need to change both of them. Luckily,
Samba affords you a limited ability to keep your passwords synchronized. Samba has a pair of
configuration
update
regular Unix
password
automatically
whenThis
the new
encrypted
Using Samba,options
Secondto
Edition
is aa user's
comprehensive
guide
to Samba
administration.
edition covers
password is changed on the system. The feature can be activated by specifying the unixpasswordsync
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
global
configuration
option:
the SWAT
graphical configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
[global]
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
unix password sync = yes
With this option enabled, Samba attempts to change the user's regular password (as root) when the
encrypted version is changed with smbpasswd. However, two other options have to be set correctly for
this to work.
The easier of the two is passwdprogram. This option simply specifies the Unix command used to change a
user's standard system password. It is set to /bin/passwd%u by default. With some Unix systems, this is
sufficient, and you do not need to change anything. Others, such as Red Hat Linux, use /usr/bin/passwd
instead. In addition, you might want to change this to another program or script at some point in the
future. For example, let's assume that you want to use a script called changepass to change a user's
password. Recall that you can use the variable %u to represent the current Unix username. So the
example becomes:
[global]
unix password sync = yes
passwd program = changepass %u
Note that this program is called as the root user when the unixpasswordsync option is set to yes. This
is because Samba does not necessarily have the old plain-text password of the user.
The harder option to configure is passwdchat. The passwdchat option works like a Unix chat script. It
specifies a series of strings to send, as well as responses to expect from the program specified by the
passwdprogram option. For example, this is what the default passwdchat looks like. The delimiters are
the spaces between each grouping of characters:
passwd chat = *old*password* %o\n *new*password* %n\n *new*password* %n\n *changed*
The first grouping represents a response expected from the password-changing program. Note that it can
contain wildcards (*), which help to generalize the chat programs to handle a variety of similar outputs.
Here,*old*password* indicates that Samba is expecting any line from the password program containing
the letters old followed by the letters password, without regard for what comes before, after, or between
them. If Samba does not receive the expected response, the password change will fail.
The second grouping indicates what Samba should send back once the data in the first grouping has been
matched. In this case, you see %o\n. This response is actually two items: the variable %o represents the
old password, while the \n is a newline character. So, in effect, this will "type" the old password into the
standard input of the password-changing program, and then "press" Enter.
Following thatTable
is another
of Contents
response grouping, followed by data that will be sent back to the passwordchanging program.
Index (In fact, this response/send pattern continues indefinitely in any standard Unix chat
script.) The script
continues until the final pattern is matched.
Reviews
Reader Reviews
You
can help match
the response strings sent from the password program with the characters listed in
Errata
Table
9-6.
In
addition,
you can use the characters listed in Table 9-7 to help formulate your response.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
ISBN: 0-596-00256-4
Pages: 556
Character
Slots: 1
Definition
Allows you to include matching strings that contain spaces. Asterisks are still considered
wildcards even inside of quotes, and you can represent a null response with empty quotes.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Table 9-7. Password chat send characters
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Character
Definition
""
%o
%n
\n
\r
\t
\s
A space
For example, you might want to change your password chat to the following entry. This handles scenarios
in which you do not have to enter the old password. In addition, this also handles the new alltokens
updatedsuccessfully string that Red Hat Linux sends:
passwd chat = *New password* %n\n *new password* %n\n *success*
Again, the default chat should be sufficient for many Unix systems. If it isn't, you can use the passwd
chatdebug global option to set up a new chat script for the password change program. The passwdchat
debug option logs everything during a password chat. This option is a simple Boolean, as shown here:
[global]
unix password sync = yes
passwd chat debug = yes
log level = 100
After you activate the password chat debug feature, all I/O received by Samba through the password
chat can be sent to the log.smbd Samba log file with a debug level of 100, which is why we entered a
newloglevel option as well. As this can often generate multitudes of error logs, it can be more efficient
to use your own scriptby setting the passwdprogram optionin place of /bin/passwd to record what
happens during the exchange. Be careful because the log file contains the passwords in plain text.
Keeping files containing plain-text passwords can (or should) be against local security policy in your
organization, and it also might raise serious legal issues. Make sure to protect your log files with strict file
permissions and to delete them as soon as you've grabbed the information you need. If possible, use the
passwdchatdebug option only while your own password is being changed.
of Contents
The operatingTable
system
on which Samba is running might have strict requirements for valid passwords to
Indeximpervious to dictionary attacks and the like. Users should be made aware of these
make them more
restrictions when
Reviews
changing their passwords.
Reader Reviews
Earlier we saidErrata
that password synchronization is limited. This is because there is no reverse
synchronization
of the encrypted smbpasswd file when a standard Unix password is updated by a user.
Using
Samba, 2nd Edition
There are various strategies to get around this, including NIS and freely available implementations of the
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Pluggable Authentication Modules (PAM) standard, but none of them really solves all the problems.
Publisher:
O'Reilly regarding passwords can be found in the in the Samba source distribution file
More
information
docs/htmldocs/ENCRYPTION.html.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
9.4.4 Slots:
Password
1
Configuration Options
The options in Table 9-8 will help you work with passwords in Samba.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Table domain
9-8. Password
options
Samba's new role as a primary
controller andconfiguration
domain member server,
its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Option
Parameters
Function
Default
Scope
Boolean
Ifyes, enables
encrypted passwords.
no
Global
unix
password
sync
Boolean
no
Global
passwd
chat
string (chat
commands)
Sequence of commands
sent to the password
program.
Global
passwd
chatdebug
Boolean
no
Global
passwd
program
string (Unix
command)
Program to be used to
change passwords.
/bin/passwd%u
Global
numeric
Number of capital-letter
permutations to attempt
when matching a client's
password.
None
Global
Boolean
no
Global
encrypt
passwords
password
level
update
encrypted
null
passwords
Boolean
no
/usr/local/samba/private/smbpasswd Global
Reviews
Reader
string Reviews
hosts
equiv
None
Global
Global
Global
Theencryptpasswords global option switches Samba from using plain-text passwords to encrypted
ISBN: 0-596-00256-4
passwords
for authentication. Encrypted passwords will be expected from clients if the option is set to
Pages:
556
yes:
Slots: 1
This is because the Unix passwd program, which is the usual target for this operation, allows root to change a
user's password without the security restriction that requests the old password of that user.
Table of Contents
Index
If set to yes, the passwdchatdebug global option logs everything sent or received by Samba during a
Reviews
password chat. All the I/O received by Samba through the password chat is sent to the Samba logs with
Reader Reviews
a debug level of 100; you must specify loglevel=100 for the information to be recorded. Section 9.4.3
Errata
earlier in this chapter describes this option in more detail. Be aware that if you do set this option, the
Using Samba, 2nd Edition
plain-text passwords will be visible in the debugging logs, which could be a security hazard if they are not
By
David Collier-Brown
, Robert
Eckstein
, Jay
Ts
properly
secured. It
is against
the
security
policy of some organizations for system administrators to
have access to users' passwords.
Publisher: O'Reilly
Pub Date: February 2003
9.4.4.5ISBN:
passwd
program
0-596-00256-4
Pages: 556
Thepasswd
option specifies a program on the Unix Samba server that Samba can use to update
Slots:program
1
the standard system password file when the encrypted password file is updated. This option defaults to
the standard passwd program, usually located in the /bin directory. The %u variable is typically used as
the requesting user when the command is executed. The actual handling of input and output to this
program during execution is handled through the passwdchat option. Section 9.4.3 earlier in this chapter
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
covers
this option
in detail.
all versions
of Samba
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
9.4.4.6
level
Windowspassword
NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
With SMB, nonencrypted (or plain-text) passwords are sent with capital letters, just like the usernames
mentioned previously. Many Unix users, however, choose passwords with both upper- and lowercase
letters. Samba, by default, only attempts to match the password entirely in lowercase letters and not
capitalizing the first letter.
Likeusernamelevel, a passwordlevel option can be used to attempt various permutations of the
password with capital letters. This option takes an integer value that specifies how many letters in the
password should be capitalized when attempting to connect to a share. You can specify this option as
follows:
[global]
password level = 3
In this case, Samba then attempts all permutations of the password it can compute having three capital
letters. The larger the number, the more computations Samba has to perform to match the password,
and the longer a connection to a specific share might take.
each time she connects to a share. When this option is enabled, you must have the encryptpasswords
option set to no so that the client passes plain-text passwords to Samba to update the files. Once each
user has connected at least once, you can set encryptedpasswords=yes, allowing you to use only the
encrypted passwords. The user must already have a valid entry in the smbpasswd file for this option to
work.
Table of Contents
Reviews
This
global option
Indextells Samba whether to allow access from users that have null passwords (encrypted or
nonencrypted) set in their accounts. The default value is no. You can override it as follows:
Reader Reviews
null passwords
= yes
Errata
Using
Samba,
2nd Edition
We highly
recommend
against doing so because of the security risks this option can present to your
system,
including inadvertent
access
to system users (such as bin) in the system password file who have
By
David Collier-Brown
, Robert Eckstein
, Jay Ts
null passwords set.
Publisher: O'Reilly
Pub Date: February 2003
9.4.4.9ISBN:
smb
passwd file
0-596-00256-4
Pages: 556
This global
identifies the location of the encrypted password database. By default, it is set to
Slots: option
1
/usr/local/samba/private/smbpasswd . You can override it as follows:
[global]
Usingsmb
Samba,
Second
is a comprehensive guide to Samba administration. This new edition covers
passwd
file Edition
= /etc/samba/smbpasswd
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
tool. on
Updated
2000, ME,
XP,Samba
the book
explores
This
location,
for example,
is common
many for
RedWindows
Hat distributions
onand
which
hasalso
been
installed
Samba's
new role
as a primary domain controller and domain member server, its support for the use of
using
an RPM
package.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
NT/2000 primary
Indexdomain controller, the PDC has a preexisting database of user accounts and group
information that
is used for authentication. It can be a big chore to transfer that database manually to the
Reviews
Unix server, and
later
maintain and synchronize the Unix and Windows databases.
Reader
Reviews
Errata
InChapter 4, we showed you how to add a Samba server as a domain member server to a network
Using Samba, 2nd Edition
having a Windows NT/2000 primary domain controller. We set security=domain in the Samba
By
David Collier-Brown
Eckstein
, Jay Ts
configuration
file to,Robert
have the
Samba
server hand off authentication to the Windows PDC. Using that
method, passwords are kept only on the PDC, but it is still necessary to set up user accounts on the Unix
sidePublisher:
to make
O'Reilly
sure each client has a valid Unix UID and group ID (GID). This is necessary for maintaining
the Pub
fileDate:
ownerships
and permissions of the Unix security model. Whenever Samba performs an operation
February 2003
on theISBN:
Unix0-596-00256-4
filesystem on behalf of the Windows client, the user must have a valid UID and GID on the
local Unix
system.
Pages: 556
Slots: 1
A facility
that has recently been added to Samba, winbind, allows the Windows PDC to handle not only
authentication, but the user and group information as well. Winbind works by extending the Unix user
and group databases beyond the standard /etc/passwd and /etc/group files such that users and groups
on the Windows PDC also exist as valid users and groups on the Unix system. The extension applies to
Using
Samba,
is a comprehensive
guide to Samba
administration.
This
new edition
covers
the
entire
UnixSecond
systemEdition
and allows
users who are members
of a Windows
domain to
perform
any action
all versions
Samba
from
2.0 to
2.2,
including
selected
features
an alpha
version
of 3.0,
as well
on
the Unix of
system
that
a local
user
would,
including
logging
in tofrom
the Unix
system
by telnet
or even
onas
SWATsystem,
graphical
configuration
tool.
Updated for
2000, ME, and XP, the book also explores
the local
using
their domain
usernames
andWindows
passwords.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
When
winbind
NT/2000/XP
is in use,
authentication
administration
and
of filesystem
user accounts
security
can be
on done
the host
on the
Unix
Windows
system,PDC,
and accessing
without
shared to
having
files
repeat
and printers
the tasks
from
on the
UnixUnix
clients.
side. This includes password expiration and allowing users to
change their passwords, which would otherwise not be practical. Aside from simplifying domain
administration and being a great time saver, winbind lets Samba be used in computing environments
where it otherwise might not be allowed.
Because this is a chapter on security, we want to point out that some issues might
relate to allowing a Windows system to authenticate users accessing a Unix
system! Whatever you might think of the relative merits of Unix and Windows
security models (and even more importantly, their implementations), one thing is
certain: adding winbind support to your Samba server greatly complicates the
authentication system overalland quite possibly allows more opportunities for
crackers.
We present winbind in this chapter not as a means of improving security, but
rather as a further example of Samba's ability to integrate itself into a modern
Windows environment.
4.
5. Configure the system to start and stop the winbindd daemon automatically.
6. Optionally, configure PAM for use with winbind.
At the time this book was written, winbind was supported only on Linux, so all of the following directions
are specific to it. Other Unix flavors might be supported at a later time. In addition, we assume you have
a Windows NT/2000 primary domain controller running on your network.
First, you will need to configure and compile Samba using the --with-winbind configure option.
Directions for Table
doingofthis
are included in Chapter 2 in Section 2.3. As usual, run make install to reinstall
Contents
the Samba binaries.
Index
Reviews
Reader Reviews
Errata
9.5.2 Configuring
nsswitch
When
is compiled
after being
configured with the --with-winbind option, the compilation process
By
DavidSamba
Collier-Brown
, Robert Eckstein
, Jay Ts
produces a library called libnss_winbind.so in the source/nsswitch directory. This library needs to be
copied
to the
/lib directory:
Publisher:
O'Reilly
Pub Date: February 2003
Also,
Pages:
556
a
symbolic
Slots: 1
The name
of this
link is correct
forSamba
Sambaadministration.
2.2.3 and Red This
Hat 7.1.
Using Samba, Second
Edition
is asymbolic
comprehensive
guide to
new The
edition covers
name
might
changewith
a
higher
version
number
in
the
extensionin
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version future
of 3.0, as well as
releases.
See the winbindd
manual
for details.
the SWAT graphical
configuration
tool. Updated
for page
Windows
2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Next, we need to modify /etc/nsswitch.conf to make the lines for passwd and group look like this:
shared files and printers from Unix clients.
passwd:
files winbind
group:
files winbind
to function, the Unix system must have a UID and GID associated with every user and group RID that is
received from the Windows primary domain controller. The winbinduid and winbindgid parameters
simply provide winbind with a range of UIDs and GIDs, respectively, that are allocated by the system
administrator for Windows NT domain users and groups. You can use whatever range you want for each;
just make sure the lowest number in the range does not conflict with any entries in your /etc/passwd or
/etc/group files at any time, either now or in the future. It is important to be conservative about this.
Once winbind adds an RID to UID/GID mapping to its database, it is very difficult to modify the mapping.
Table of Contents
Index
Errata
Be careful when adding local users after domain users have started accessing the
Samba server. The domain users will have entries created for them by winbind in
Publisher: O'Reilly
/etc/passwd, with UIDs in the range you specify. If you are using a method of
Pub Date: February
2003 new accounts that automatically assigns UIDs, it might choose UIDs by
creating
ISBN: 0-596-00256-4
adding 1 to the highest UID assigned thus far, which will be the most recent UID
Pages: 556 added by winbind. (This is the case on Red Hat Linux, with the useradd script, for
example.) The UID for the new local user will be within the range allocated for
Slots: 1
winbind, which will have undesired effects. Make sure to add new local users using
a method that assigns them UIDs in the proper range. For example, you can use
the-u option of useradd to specify the UID to assign to the new user.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Restart
the Samba
daemons
to to
put2.2,
your
changesselected
to the configuration
effect.
If you
haveasnot
all versions
of Samba
from 2.0
including
features fromfile
aninto
alpha
version
of 3.0,
well as
already
done
so
while
adding
your
Samba
server
as
a
domain
member
server,
you
must
issue
the
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
command:
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
#
smbpasswd
-j printers
domain from
-r Unix
pdc -U
Administrator
shared
files and
clients.
as we described in Chapter 4. At this point, you can start the winbindd daemon:
#winbindd
You might want to run a ps ax command to see that the winbindd daemon is running. Now, to make sure
everything we've done up to this point works, we can use Samba's wbinfo command:
$wbinfo -u
METRAN\Administrator
METRAN\bebe
METRAN\Guest
METRAN\jay
METRAN\linda
$wbinfo -g
METRAN\Domain Admins
METRAN\Domain Guests
METRAN\Domain Users
The-u option queries the domain controller for a list of domain users, and the -g option asks for the list
of groups. The output shows that the Samba host system can query the Windows PDC through winbind.
Another thing to check is the list of users and groups, using the getent command:
#getent passwd
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:
daemon:x:2:2:daemon:/sbin:
Table of Contents
Index ...
... deleted
Reviews
jay:x:500:500:Jay
Ts:/home/jay:/bin/bash
Reader Reviews
Errata
rik:x:501:501::/home/rik:/bin/bash
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
METRAN\Administrator:x:10000:10000::/home/METRAN/administrator:/bin/bash
Publisher: O'Reilly
METRAN\bebe:x:10001:10000:Bebe
Larta:/home/METRAN/bebe:/bin/bash
Pub Date: February 2003
ISBN: 0-596-00256-4
METRAN\Guest:x:10002:10000::/home/METRAN/guest:/bin/bash
Pages: 556
METRAN\jay:x:10003:10000:Jay
Ts:/home/METRAN/jay:/bin/bash
Slots: 1
METRAN\linda:x:10004:10000:Linda Lewis:/home/METRAN/linda:/bin/bash
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
# getent group
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
root:x:0:root
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
bin:x:1:root,bin,daemon
daemon:x:2:root,bin,daemon
... deleted ...
jay:x:500:
rik:x:501:
METRAN\Domain Admins:x:10001:METRAN\Administrator
METRAN\Domain Guests:x:10002:METRAN\Guest
METRAN\Domain Users:x:10000:METRAN\Administrator,METRAN\jay,METRAN\linda,METRAN\bebe
This shows that the Linux system is finding the domain users and groups through winbind, in addition to
those in the /etc/passwd and /etc/group files. If this part doesn't work as shown earlier, with the domain
users and groups listed after the local ones, check to make sure you made the symbolic link to
libnss_winbind.so in /lib correctly.
Now you can try connecting to a Samba share from a Windows system using a domain account. You can
either log on to the domain from a Windows NT/2000/XP workstation or use smbclient with the -U option
to specify a username.
If you get errors while attempting to log on to the domain, it is probably because
you had previously configured the client system with a computer account on
another domain controller. Commonly, you get a dialog box that says, "The domain
NAME is not available." On a Windows 2000 system, the fix is to log in to the system
as an administrative user and open the Control Panel, double-click the System icon,
click the Network Identification tab, then click the Properties button. In the dialog
that comes up, click the "Workgroup:" radio button and fill in the name of the
workgroup (you can use the same name as the domain). Click the OK buttons in
Table of Contents
the dialogs, and reboot if requested.
Index
Reviews
Reader
againReviews
as the administrative user and repeat the previous directions, but change
Errata
from the workgroup back to the domain. This creates a new computer account that
This removes the computer account from the primary domain controller. Now log in
backup
domain
ByDavid Collier-Brown
, Robert
Ecksteincontrollers,
, Jay Ts
Publisher: O'Reilly
If you are using Windows NT/XP, the method is slightly different. For the exact
procedure, see the section in Chapter 4 that is specific to your Windows version.
ISBN: 0-596-00256-4
Pages: 556
After logging in as a domain user, try creating a file or two in a Samba share. (You might need to change
Slots: 1
the permissions
on the shared directorysay, to 777to allow this access. This is very permissive, but
after you finish reading this section, you will understand how to change ownership and permissions on
the directory to restrict access to selected domain users.) After you've created files by one or more
domain users, take a look at the directory's contents from a Linux shell. You will see something like this:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
$
lsversions
-l /u of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
all
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
-rwxrw-rw1 as
METRAN\b
METRAN\D
0 and
Apr domain
13 00:00
bebes-file.doc
Samba's new role
a primary
domain controller
member
server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
-rwxrw-rwMETRAN\l
0 Apr 12 23:58 lindas-file.doc
shared files and 1
printers
fromMETRAN\D
Unix clients.
drwxrwxr-x
6 jay
jay
-rwxrw-rw-
1 10001
10000
-rwxrw-rw-
1 10004
10000
drwxrwxr-x
6 500
500
$ ls -ln /u
total 4
We can even use the domain usernames and groups from the Linux shell:
#chown 'METRAN\linda:METRAN\Domain Users' /u
#ls -ldu /u
drwxrwxrwx
3 METRAN\l METRAN\D
3 10004
#ls -ldn /u
drwxrwxrwx
10000
Notice how the owner and group are listed as being those of the domain user and group. Unfortunately,
the GNU ls command won't show the full names of the domain users and groups, but we can use the -ln
listing to show the UIDs and GIDs and then translate with the wbinfo command:
$wbinfo -s `wbinfo -U 10004`
METRAN\LINDA 1
$wbinfo -s `wbinfo -G 10000`
METRAN\Domain Users 2
(It's a bit messy, but it works, and it shows that the winbind system is working!) At this point, you might
want to modify your /etc/rc.d/init.d/smb script to start and stop the winbindd daemon automatically
along with the smbd and nmbd daemons. Starting with the script we presented in Chapter 2, we first add
Table
of Contents
this code to the
start(
) function:
Index
echo
-n $"Starting
Reader Reviews
/usr/local/samba/bin/winbindd
Errata
Using Samba, 2nd Edition
ERROR2=$?
if [ $ERROR2 -ne 0 ]
Publisher: O'Reilly
then
Pub Date: February
2003
ISBN: 0-596-00256-4
ERROR=1
Pages: 556
fi
Slots: 1
echo
Using
Samba,code
Second
Edition
is a comprehensive
guide
Samba
administration.
This
new statement.
edition covers
The previous
should
be located
after the code
that to
starts
nmbd
and before the
return
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
We start winbindd after nmbd because winbindd needs nmbd to be running to work
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
properly.
shared files and printers from Unix clients.
passwords submitted by users and reject any attempts to use a longer or shorter password. PAM would
then be reconfigured to include the new module for services such as ftp, console login, and GUI login that
call upon PAM to authenticate users.
If you are not already familiar with PAM, we suggest you read the documentation provided with the Linux
PAM package before continuing. On most Linux systems, it is located in the /usr/share/doc directory
hierarchy. Another resource is the Linux-PAM System Administrator's Guide , which you can find on the
Internet at http://www.kernel.org/pub/linux/libs/pam.
The rest of this
Table
section
of Contents
is about using the PAM module provided in the Samba distribution to enable
Windows domain
users to authenticate on the Linux system hosting Samba. Depending on which services
Index
you choose toReviews
configure, this allows Windows domain users to log in on a local console (or through
Reviews
Linux system,Errata
or use other services normally limited to users who have an account on the Linux system.
The PAM
module
authenticates Windows domain users by querying winbind, which passes the
Using
Samba,
2nd Edition
authentication off to a Windows NT domain controller.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
As an example, we will show how to allow Windows domain users to log in to a text console on the Linux
Publisher:
system
andO'Reilly
get a command shell and home directory. The method used in our example can be applied
(with
to2003
other services.
Pubvariations)
Date: February
ISBN: 0-596-00256-4
All users who can log in to the Linux system need a shell and a home directory. Unix and Linux keep this
Pages: 556
user information in the password file (/etc/passwd ), but information about Windows users isn't located
Slots: 1
there. Instead, in the Samba configuration file, we add the following to notify winbind what the shell and
home directory for Windows domain users will be:
[global]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
template
of Samba
shell from
= /bin/bash
2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
template
new role
homedir
as a primary
= /home/%D/%U
domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
The
firstfiles
lineand
setsprinters
the template
shell
parameter, which tells winbind what shell to use for domain users
shared
from Unix
clients.
that are logging in to the Unix host. The templatehomedir parameter specifies the location of users'
home directories. The %D variable is replaced by the name of the domain in which the user's account
resides, and %U is replaced by the user's username in that domain.
Before the domain users can successfully log in, their home directories must be created manually. To add
a single account for linda in the METRAN domain, we would use these commands:
#mkdir /home/METRAN
#chmod 755 /home/METRAN
#mkdir /home/METRAN/linda
#chown 'METRAN\linda:METRAN\Domain Users' /home/METRAN/linda
#chmod 700 /home/METRAN/linda
One side effect of creating the home directories is that if the Samba server is
configured with a [homes] share, the domain users can see and access their home
directories through Samba's file sharing.
Next, we need to compile and install the PAM module in the Samba distribution. From the source
directory in the Samba distribution, issue the following commands:
#make nsswitch/pam_winbind.so
#cp nsswitch/pam_winbind.so /lib/security
Index
our
configuration
goes
awry, all users (including root) will be locked out of the system. In case the worst
Reader
Reviews
happens,
we
would
reboot
into single-user mode (by typing linuxsingle at the LILO: prompt) or boot a
Errata
rescue
disk,
and
then
we
would
issue these two commands:
Using Samba, 2nd Edition
By
David
Collier-Brown
, Robert Eckstein, Jay Ts
#mv
/etc/pam.d
/etc/pam.d.bad
#mvPublisher:
/etc/pam.d.backup
/etc/pam.d
O'Reilly
Pub Date: February 2003
Be very
careful to make sure you can recover from any errors you make because when PAM encounters
ISBN: 0-596-00256-4
any configuration information it doesn't understand, its action is not to allow access. This means you
Pages: 556
must be sure to enter everything correctly! You might want to leave yourself logged in as root on a spare
1
virtual Slots:
terminal
while you are modifying your PAM configuration to ensure yourself a means of easy
recovery.
In the /etc/pam.d directory, you will encounter a file for each service that uses PAM. We are interested
UsinginSamba,
only
the file Second
corresponding
Edition to
is a
the
comprehensive
login service, guide
which to
is Samba
called login.
administration.
It containsThis
the following
new edition
lines:
covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
auth
required
/lib/security/pam_securetty.so
the SWAT graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
auth
requiredauthentication
/lib/security/pam_stack.so
Windows NT/2000/XP
and filesystem securityservice=system-auth
on the host Unix system, and accessing
shared files and printers from Unix clients.
auth
required
/lib/security/pam_nologin.so
account
required
/lib/security/pam_stack.so service=system-auth
password
required
/lib/security/pam_stack.so service=system-auth
session
required
/lib/security/pam_stack.so service=system-auth
session
optional
/lib/security/pam_console.so
The lines starting with auth are related to the function of authenticationthat is, printing a password
prompt, accepting the password, verifying that it is correct, and matching the user to a valid user and
group ID. The line starting with account is for account management, which allows access to be controlled
by other factors, such as what times during the day a user is allowed access. We are not concerned with
the lines starting with password or session because winbind does not add to either of those functions.
The third column lists the PAM module, possibly with arguments, that is called in for the task. The
pam_stack.so module has been added by Red Hat to act somewhat like a macro or a subroutine. It calls
the file in the pam.d directory named by the service argument. In this case, the file /etc/pam.d/systemauth contains a common set of lines that are used as a default for many services. Because we want to
customize the login service for winbind, we first replace the pam_stack.so lines for auth and account
with the auth and account lines from /etc/pam.d/system-auth . This yields:
auth
required
/lib/security/pam_securetty.so
auth
required
/lib/security/pam_env.so
auth
sufficient
auth
required
/lib/security/pam_deny.so
auth
required
/lib/security/pam_nologin.so
account
required
/lib/security/pam_unix.so
password
required
/lib/security/pam_stack.so service=system-auth
session
required
/lib/security/pam_stack.so service=system-auth
session
optional
/lib/security/pam_console.so
Table of Contents
To add winbind
Index
support, we need to add a line in both the auth and account sections to call the
pam_winbind.so
Reviews
module:
Reader Reviews
auth
required
Errata
/lib/security/pam_securetty.so
auth
required
/lib/security/pam_env.so
auth
sufficient
/lib/security/pam_winbind.so
Publisher: O'Reilly
auth
Pub Date: February
sufficient
2003
ISBN: 0-596-00256-4
auth
auth
required
Pages: 556
Slots: 1
account
/lib/security/pam_deny.so
required
/lib/security/pam_nologin.so
sufficient
/lib/security/pam_winbind.so
Using
Samba,required
Second Edition
is a comprehensive guide to Samba administration. This new edition covers
account
/lib/security/pam_unix.so
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical
configuration
tool. Updated for Windowsservice=system-auth
2000, ME, and XP, the book also explores
password
required
/lib/security/pam_stack.so
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
and filesystem securityservice=system-auth
on the host Unix system, and accessing
session NT/2000/XP
requiredauthentication
/lib/security/pam_stack.so
shared files and printers from Unix clients.
session
optional
/lib/security/pam_console.so
The keywords required and sufficient in the second column are significant. The keyword required
specifies that the result returned by the module (either to pass or fail the authentication) must be taken
into account, whereas the keyword sufficient specifies that if the module successfully authenticates the
user, no further lines need to be processed. By specifying sufficient for the pam_winbind.so module,
we let winbind attempt to authenticate users, and if it succeeds, the PAM system returns to the
application. If the pam_winbind.so module doesn't find the user or the password does not match, the
PAM system continues with the next line, which performs authentication according to the usual Linux user
authentication. This way, both domain users and local users can log in.
Notice that we also added the use_first_pass argument to the pam_unix.so module in the auth section.
By default, both the pam_winbind.so and pam_unix.so modules print a password prompt and accept a
password. In cases where users are logging in to the Linux system using their local accounts, this would
require them to enter their password twice. The user_first_pass argument tells the pam_unix.so
module to reuse the password that was given to the pam_winbind.so module, which results in users
having to enter the password only once.
After modifying the login configuration file, switch to a spare virtual console and make sure you can still
log in using a regular Linux account. If not, check your modifications carefully and try again until you get
it right. Then log in using a domain user account from the Windows PDC database to check that the
winbind authentication works. You will need to specify the username in DOMAIN\user format, like this:
login: METRAN\linda
Password:
More information on configuring winbind can be found in the Samba source distribution file
docs/htmldocs/winbind.html , and in the winbindd manual page. If you would like to learn more about
configuring PAM, we recommend the web page http://www.kernel.org/pub/linux/libs/pam/ as a starting
place. Some of the documentation for Linux PAM, including Red Hat's extensions, can also be found on
Red Hat Linux in /usr/share/doc/pam-version.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Using Option
Samba, 2nd Edition
Parameters
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
winbind
separator
string (single
character)
Function
Default
Scope
Backslash
(\)
Global
None
Global
Publisher: O'Reilly
string
2003 (numeric
range)
ISBN: 0-596-00256-4
Pub Date:uid
February
winbind
Pages: 556
winbind gid
string (numeric
range)
None
Global
winbind cache
time
numeric
15
Global
Slots: 1
Using
template
Samba, Second
Edition
is a comprehensive
to Samba
string
(directory
Directory toguide
be used
as the administration.
home directory This new edition covers
/home/%D/%U Global
all
homedir
versions of Samba
from 2.0 to 2.2, including
selected
features
from an alpha version of 3.0, as well as
name)
of the logged-in
domain
user
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
string
(command
program
todomain
use as the
logged-in
Samba's
new
role as
a primary
domainThe
controller
and
member
server, its support
for the use
of
template
shell
/bin/false
Global
name)
domain
user's
shell
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
highest
of Contents
UID assigned thus far.
Index
Errata
There
is no default
for winbinduid, so you must specify it in your Samba configuration file for winbind to
Reviews
work.
Reader Reviews
Using Samba, 2nd Edition
9.5.5.3
winbind gid
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
This option works like winbinduid, except that it is for allocating a range of GIDs for use with winbindd.
Publisher: O'Reilly
You might not need to allocate as many GIDs as UIDs because you probably have relatively few domain
Pub Date: February 2003
groups that need corresponding GIDs. (In many cases, users are all members of the Domain Users
0-596-00256-4
group,ISBN:
requiring
only one GID.) However, it is best to play it safe, so make sure to allocate many more
Pages:
556
GIDs than you think you will need.
Slots: 1
As with winbinduid, if you are using a method of adding new local users to your Unix host that
automatically assigns GIDs, either make sure the method used doesn't conflict with winbind or set the
GIDs manually.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
There is no default for winbindgid, so you must specify it in your Samba configuration file for winbind to
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
work.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
9.5.5.4
winbind
cachefrom
timeUnix clients.
shared files
and printers
Thewinbindd daemon maintains a cache of user and group data that has been retrieved from the
Windows PDC to reduce network queries and increase performance. The winbindcachetime parameter
allows the amount of time (in seconds) winbindd can use the cached data before querying the PDC to
check for an update. By default, this interval is set to 15 seconds. This means that when any part of a
user or group account on the PDC is modified, it can take up to 15 seconds for winbindd to update its
own database.
logins for domain users, set templateshell to a valid command shell (or other program) that you want
to act as the textual interface the domain users will receive when logged in. A common setting on Linux
would be:
[global]
template shell = /bin/bash
which would give users the Bash shell for their interactive login sessions.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
organizations, using a Unix system as the print server has led to happier system administrators and
Index
users alike, due
to the reduced frequency of problems.
Reviews
Errata
also send Unix documents to printers shared by Windows systems. In this chapter, we discuss how to get
Using Samba,
2nd Edition
printers
configured
to work in either direction.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
We focus in this chapter on getting Samba to serve up printers that are already functioning on the Unix
host. We include just a few basics about setting up printers on Unix. Good references for this topic
Publisher: O'Reilly
include
Network Printing,Essential System Administration, and Running Linux, all by O'Reilly and
Pub Date: February 2003
Associates.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
Index
Reviews 10-1. A Samba printer in the Network Neighborhood
Figure
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
To
administer
with Samba,
you should understand
the basic
process by which
printing
takes
Using
Samba, printers
Second Edition
is a comprehensive
guide to Samba
administration.
This new
edition
covers
place
on
a
network.
On
the
client
system,
the
application
software
prints
by
utilizing
the
system's
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, asprinter
well as
driver
for the
printerconfiguration
that will be creating
the actual
output. It2000,
is theME,
printer
software
running
on
the SWAT
graphical
tool. Updated
for Windows
and driver
XP, the
book also
explores
the
client
system
that
translates
the
application's
high-level
calls
into
a
stream
of
binary
data
specific
Samba's new role as a primary domain controller and domain member server, its support for the use to
of
the
modelNT/2000/XP
of printer inauthentication
use. In the case
offilesystem
a serial, parallel,
thesystem,
data is and
stored
in a
Windows
and
securityoronUSB
theprinter,
host Unix
accessing
temporary
in printers
the localfrom
system's
printer queue and then sent through the respective port directly to
shared filesfile
and
Unix clients.
the printer. For a network printer, the file is sent over the network.
Because the data has already been processed through a printer driver by the time
it reaches the Samba host, make sure the printer on the Unix system is configured
without any printer driver and that it will print whatever data it receives in raw
form. If you already have the printer configured for use by Unix applications, you
might need to set up another queue for it to print documents received from
Windows clients correctly.
Sending a print job to a printer on a Samba server involves four steps:
1. Opening and authenticating a connection to the printer share
2. Copying the file over the network
3. Closing the connection
4. Printing and deleting the copy of the file
When a print job arrives at a Samba server, the print data is temporarily written to disk in the directory
specified by the path option of the printer share. Samba then executes a Unix print command to send
that datafile to the printer. The job is then printed as the authenticated user of the share. Note that this
can be the guest user, depending on how the share is configured.
Linux, which uses a BSD-style printing system, a command that does this is:
lpr -r -Pprinter file
This command tells lpr to retrieve the name of the printer in the system configuration file (/etc/printcap)
and interpret the rules it finds there to decide how to process the data and which physical device to send
it to. Note that because the -r option has been specified, the file will be deleted after it has been printed.
Of course, the file removed is just a copy stored on the Samba server; the original document on the
client is unaffected.
Table of Contents
The
process isIndex
similar on System V Unix. Here, printing and deleting become a compound command:
Reviews
lp
-dprinterReader
-s file;
rm file
Reviews
Errata
In this case, the /etc/printcap file is replaced with a different set of configuration files residing in
Using Samba, 2nd Edition
/usr/spool/lp. Because the lp command has no option to delete the file after it is printed, we have added
By
David
Collier-Brown, Robert Eckstein, Jay Ts
the
rm command.
Publisher: O'Reilly
Pub Date:
February 2003 Printing Setup
10.1.2
A Minimal
ISBN: 0-596-00256-4
Pages:with
556
start
Let's
a simple yet illustrative printing share. Assuming that you're on a Linux system and you
1 called netprinter listed in the printer capabilities file, the following addition to your
have aSlots:
printer
smb.conf file makes the printer accessible through the network:
[printer1]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
printable
= yesfrom 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
all versions
of Samba
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
print
command
/usr/bin/lpr
-r %sand domain member server, its support for the use of
Samba's
new
role as =
a primary
domain-P%p
controller
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
printer
= netprinter
shared
files and
printers from Unix clients.
printing = BSD
path = /var/tmp
The variable %s in the printcommand option is replaced with the name of the file to be printed when
Samba executes the command. There are four Samba configuration-file variables specifically for use with
printing options. They are shown in Table 10-1.
Definition
%s
%f
The name of the file itself (without the preceding path) on the Samba server to be printed
%p
%j
The number of the print job (for use with lprm,lppause, and lpresume)
For other flavors of Unix, it is necessary to modify both the printing and printcommand options. For
System V Unix, we would specify:
[printer1]
printing = SYSV
print command = lp -d%p -s %s; rm %s
With the printing=SYSV parameter, we notify Samba that the local printing system uses the System V
Unix method. As mentioned earlier, the %p variable resolves to the name of the printer, while the %s
variable resolves to the name of the file.
Clients might need to request the status of a print job sent to the Samba server. Because Samba sends
print jobs to the Unix printing system for spooling, there might be a number of jobs in the queue at any
given time. Consequently, Samba needs to communicate to the client not only the status of the current
printing job, but also which documents are waiting to be printed on that printer. Samba also has to
provide the client
Tablethe
of Contents
ability to pause print jobs, resume print jobs, and remove print jobs from the
printing queue.
Samba provides options for each of these tasks. As you might expect, they borrow
Index
functionality from
the following existing Unix commands:
Reviews
Reader Reviews
lpq
Errata
lppause
Publisher: O'Reilly
Pub Date: February 2003
lpresume
ISBN: 0-596-00256-4
Pages:
556
cover
these
We
options in more detail later in this chapter. For the most part, Samba provides reasonable
defaultSlots:
values
1 for them based on the value of the printing configuration option, so you can probably get
by without having to formulate your own commands for them.
Here are a few important items to remember about printing shares:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
from 2.0=yes
to 2.2,
including
selected
features
from an alpha
version
ofknows
3.0, asthey
well as
You must
put printable
in all
printer shares
(even
[printers])
so that
Samba
the SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
are printer shares. If you forget, the shares will be unusable for printing and will instead be treated
Samba's
newshares.
role as a primary domain controller and domain member server, its support for the use of
as disk
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
andthe
printers
from Unix clients.
If files
you set
path configuration
option in the printer section, any files sent to the printer(s) will be
copied to the directory you specify instead of to the default location of /tmp. Because the amount of
disk space allocated to /tmp can be relatively small in some Unix operating systems, many
administrators prefer to use /var/tmp, /var/spool/tmp , or some other directory instead.
If you set guestok=yes in a printer share and Samba is configured for share-level security,
anyone can send data to the printer as the guestaccount user.
Using one or more Samba machines as a print server gives you a great deal of flexibility on your LAN.
You can easily partition your available printers, restricting some to members of one department, or you
can maintain a bank of printers available to all. In addition, you can restrict a printer to a select few by
adding the validusers option to its share definition:
[deskjet]
printable = yes
path = /var/spool/samba/print
valid users = elizabeth cozy jack heather alexander lina emerald
All the other share accessibility options work for printing shares as well.
Recall that Samba obeys the following rules when a client requests a share that has not been created
with an explicit share definition in the smb.conf file:
If the share name matches a username in the system password file and a [homes] share exists, a
new share is created with the name of the user and is initialized using the values given in the
[homes] and [global] sections.
Otherwise, if the name matches a printer in the system printer capabilities file and a [printers]
share exists,
share is created with the name of the printer and initialized using the values
Table a
ofnew
Contents
given in Index
the [printers] section. (Variables in the [global] section do not apply here.)
Reviews
If neither of those succeeds, Samba looks for a defaultservice share. If none is found, it returns
Reader Reviews
an error.
Errata
This brings to light an important point: be careful that you do not give a printer the same name as a
By
David
Collier-Brown
, Robert
Eckstein
, Jay Ts
user.
Otherwise,
users
end
up connecting
to a disk share when they might have wanted a printer share
instead.
Publisher: O'Reilly
Here is an example [printers] share for a Linux system. Some of these options are already defaults;
Pub Date: February 2003
however, we have listed them anyway for illustrative purposes:
ISBN: 0-596-00256-4
Pages: 556
[printers]
Slots: 1
printable = yes
printing = BSD
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
printcap
name =from
/etc/printcap
all versions
of Samba
2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
print
command
/usr/bin/lpr
-r %sand domain member server, its support for the use of
Samba's
new
role as =
a primary
domain-P%p
controller
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
path
/var/spool/lpd/tmp
shared
files= and
printers from Unix clients.
min print space = 2000
Here, we've given Samba global options that specify the printing type (BSD), a print command to send
data to the printer and later remove the temporary file, the location of our printer capabilities file, and a
minimum disk space for printing of 2MB.
In addition, we've created a [printers] share for each system printer. Our temporary spooling directory
is specified by the path option: /var/spool/lpd/tmp. Each share is marked as printablethis is a
necessary option, even in the [printers] section.
textfile
The job appears (briefly) in the Samba spool directory specified by the path.
The job shows up in your print system's spool directory.
The job disappears from the spool directory that Samba used.
Ifsmbclient cannot print, you can reset the printcommand option to collect debugging information:
Table
of Contents
print command
= echo
"printed %s on %p" >>/tmp/printlog
Index
Acommon problem
Reviews
with Samba printer configuration is forgetting to use the full pathnames for
commands. Another
frequent problem is not having the correct permissions on the spooling directory.[1]
Reader Reviews
As usual, check
your Samba log files and system log files for error messages. If you use BSD printing,
Errata
you can
change
the lp keyword in the printer's printcap entry to something other than /dev/null, allowing
Using
Samba,
2nd Edition
you to collect error messages from the printing system.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
[1]
If you are using Linux, you can use the checkpc command to check for this type of error.
Publisher: O'Reilly
Pub Date: February 2003
More information
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
In this
dialog box, you should see a large list of manufacturers and models for a huge number of printers.
Pub Date:
February 2003 of your printer in the left side of the dialog box, and then the exact model of the
Select
the manufacturer
0-596-00256-4
printerISBN:
in the
list on the right side.
Pages: 556
In some
cases,
you might not find your printer in the list, or the version of the printer driver included
Slots:
1
with Windows might be out of date. In cases such as these, consult the printer manufacturer's
documentation on how to install the driver. Typically, you will click the Have Disk... button to install the
driver from a CD-ROM or disk file.
Using
Second
Editionon
is the
a comprehensive
guideit's
toaSamba
administration.
ThisApple
new edition
If you Samba,
don't see
your printer
list, but you know
PostScript
printer, select
as the covers
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as well as
manufacturer and Apple LaserWriter as the model. This will give you the most basic PostScript printer
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
setupand arguably one of the most reliable. If you already have PostScript printers attached, you will
Samba's
role
as a primary
domain
and domain
member
its support
the use
be asked new
about
replacing
or reusing
thecontroller
existing driver.
Be aware
that ifserver,
you replace
it withfor
a new
one,of
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
you might make your other printers fail. Therefore, we recommend you keep using your existing printer
shared
andas
printers
Unixproperly.
clients.
drivers files
as long
they'refrom
working
Click the Next > or OK button. On Windows 95/98/Me, the Printer Wizard asks you to name the printer.
On Windows NT/2000/XP, you need to right-click the printer's icon and select Properties to assign the
printer a name. Figure 10-3 shows how we've named our printer to show that it's shared by the mixtec
Samba server.
Finally, on Windows 95/98/Me the Printing Wizard asks if it should print a test page. Click the "Yes" radio
button, then the Finish button, and you should be presented with the dialog box shown in Figure 10-4.
On Windows NT/2000/XP, the printer test function is also accessed through the printer's Properties dialog
box.
Table of Contents
Index
Reviews
Reader Reviews
Errata
If the test printing was unsuccessful, click the No button and the Printing Wizard will walk you through
some debugging steps for the client side of the process. If the test printing does work, the remote printer
will Publisher:
now be O'Reilly
available to all Windows applications through the File and Print menu items.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of
Index
Reviews
Reader Windows
Reviews
10.2.1 Sharing
Printers
Errata
Sharing printers on Windows is not unlike sharing files. In fact, it is a little simpler. Open the Control
By
Davidthen
Collier-Brown
, Robertthe
Eckstein
, Jay Ts
Panel,
double-click
Printers
icon to open the Printers window. Right-click the icon for the printer
you want to share, and select Sharing.... This opens the dialog box shown in Figure 10-5 for a Windows
98 system,
or Figure 10-6 on a Windows 2000 system. (The dialog box appears slightly different on other
Publisher: O'Reilly
Windows
versions,
but functions almost identically.)
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
On Windows 95/98/Me systems, you may need to run file sharing in share-level
(rather than user-level) access control mode to access a shared printer from
Samba. To check or set this mode, go to Control Panel, then double-click on
Network, then click on the Access Control tab. More detailed information on this
can be found in Chapter 5.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration
Figure 10-5.
tool. Updated
Sharing
for printers
Windows 2000,
on Windows
ME, and XP, the
98 book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Slots: 1
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
Click the "Shared as" radio button, then click the OK button. The printer is now accessible by other
ISBN: 0-596-00256-4
systems on the network.
Pages: 556
Slots: 1
If you are using the version of Samba installed from an RPM file as on Red Hat
Linux, you might be able to skip these directions and use the printconf tool, which
has support for SMB printers. Unfortunately, this tool might not work correctly if
you have installed Samba from the Samba source distribution.
Here is the entry we added to our /etc/printcap.local file to support our Hewlett-Packard DeskJet 932C
printer, which is shared by maya, a Windows 98 system:
lp|maya-hp932c:\
:cm=HP 932C on maya:\
:sd=/var/spool/lpd/maya:\
:af=/var/spool/lpd/maya/acct:\
:if=/usr/local/samba/bin/smbprint:\
:mx=0:\
:lp=/dev/null:
The first line creates names for the printer. We are calling it both maya-hp932c, to describe its location on
the network and the type of printer, and lp so that programs will use it as the default printer. The rest of
the lines specify keywords and values. The cm keyword allows us to assign a comment string to the
printer. The sd and af keywords assign the printer's spool directory and accounting files, respectively.
Theif keyword assigns the print filter. We are using the smbprint command to send the output to the
shared SMB printer. The mx keyword is set to zero to allow any size file to be printed, and lp is set to
/dev/null to discard
messages.
Table oferror
Contents
Index
Errata
You
can followReviews
our model to create an entry for your own printer. If you want to go beyond the
capabilities
we
used, refer to your system's printcap(5) manual page for a complete listing of keywords.
Reader Reviews
Go to your Samba source distribution's root directory, and install the smbprint program like this:
Using Samba, 2nd Edition
#
examples/printing/smbprint
/usr/local/samba/bin
Bycp
David
Collier-Brown, Robert Eckstein, Jay Ts
We Publisher:
next create
the printer's spool directory:
O'Reilly
Date: February 2003
#cdPub
/var/spool/lpd
ISBN: 0-596-00256-4
Pages:
556
#mkdir
maya
Slots: 1
Table of Contents
following entries would be correct for the service in the previous example:
Index
Reviews
server
= maya
Reader Reviews
service
Errata = hp
password = ""
O'Reilly
2.Publisher:
Run the
following commands, which create a reference for the new printer (which we are naming
Pub
Date: February in
2003
hp_printer)
the printer capabilities file:
ISBN: 0-596-00256-4
lpadmin
Pages:#556
Slots: 1
#enable hp_printer
#accept hp_printer
Using
Samba,
Second
a comprehensive
guide
administration.
new
edition
covers
After you've
done
that,Edition
restartisthe
Samba daemons
andto
trySamba
printing
to hp_printerThis
using
any
standard
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as
well
as
Unix program.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
10.2.2.3
CUPS printers
shared files and printers from Unix clients.
CUPS[2] uses a set of modules, called backends, to send print jobs to various destinations, such as local
printers attached to parallel, serial, or Universal Serial Bus (USB) ports, or over the network using Unix
line printer daemon (LPD) protocol, Internet Printing Protocol (IPP), AppleTalk Printer Access Protocol
(PAP), and so on. The software package does not come with a backend for SMB; the Samba suite
includes the smbspool utility for this purpose.
[2]
CUPS is open source software (http://www.opensource.org) developed by Easy Software Products. For more
information, visit http://www.cups.org.
To enable printing to remote SMB printers using CUPS, create a symbolic link named smb in the CUPS
backend directory pointing to smbspool. Depending on installation options, these could be in a number of
places in the directory hierarchy, so be sure to check your system. Using a common default installation,
the command would look like this:
#ln -s /usr/local/samba/bin/smbspool /usr/lib/cups/backend/smb
Issue a HUP signal to the CUPS daemon, cupsd, and check for the existence of SMB support with the
lpinfo -v command. Its output should now include a line that says networksmb.
To add a printer, use the CUPS web interface, accessible on the local system at http://localhost:631/, or
use the lpadmin command:
#lpadmin -p hp932c -E -v smb://maya/hp932c -D "HP 932C on maya"
This creates and enables the new print spool called hp932c. The -v argument specifies the printer device,
which in this case is accessed over the network using an SMB URI. If the printer is not guest-accessible,
you'll need to provide a username and password in the URI. The full format is as follows:
smb://[username[:password]@][workgroup/]server/printshare
Thelpadmin command makes changes to /etc/cups/printers.conf and sends a HUP signal to the cupsd
daemon, resulting in the creation of a local raw printer spool. In this example, print data is passed in raw
format to the Windows system, which has the necessary printer drivers and printer description files to
format the data appropriately. The -D option is used to give the printer a comment string.
Once you have the printer set up, it's time to test it out. CUPS understands both BSD-style and System
V-style printing commands, so you can use whichever is more comfortable. Using the BSD lpr command,
try something like:
$lpr -P hp932c textfile
Table of Contents
You
should now
be set up to use the printer from any application on the Unix system.
Index
Reviews
Reader Reviews
ErrataPrinting Options
10.2.3 Samba
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Option
Parameters
Function
Default
Scope
bsd,sysv,cups,hpux,
Printing system type of the
Systemprinting
aix,qnx,plp,softq, or
Share
Samba
host
dependent
Using Samba, Second
Edition is a comprehensive guide to Samba administration. This
new edition covers
lprng
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
printable
the
SWAT graphicalboolean
configuration tool. Updated Marks
for Windows
ME, andshare
XP, theno
book also explores
a share2000,
as a printing
Share
(print ok)
Samba's
new role as a primary domain controller and domain member server, its support for the use of
Windows
the host
system,
and accessing
printer NT/2000/XP authentication and filesystem
Namesecurity
for the on
printer
that Unix
is shown
Systemstringfrom
(Unix
printer
name)
Share
shared
files name)
and printers
Unix
clients.
(printer
to clients
dependent
lpq cache time
postscript
10
Global
boolean
Share
load printers
boolean
yes
Global
print command
See below
Share
lpq command
See below
Share
lprm command
See below
Share
lppause
command
See below
Share
lpresume
command
See below
Share
string (filename)
Systemdependent
Global
printcap name
(printcap)
min print
space
Share
queuepause
command
See below
Share
queueresume
command
Share
Table of Contents
Index
Reviews
Reader Reviews
10.2.3.1 printing
Theprinting configuration option tells Samba which printing system to use. There are several different
Errata
families of commands to control printing and print statusing. Samba supports seven different types, as
Using Samba, 2nd Edition
shown in Table 10-3.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Variable
Slots: 1
BSD
Definition
SYSV
System V
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
CUPS
System
all
versions Common
of SambaUnix
fromPrinting
2.0 to 2.2,
including selected features from an alpha version of 3.0, as well as
the
SWAT
graphical
configuration
tool.
AIX
IBM's AIX operating systemUpdated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
HPUX
Hewlett-Packard
Unix
Windows
NT/2000/XP
authentication
and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
QNX
QNX Realtime Operating System
LPRNG
SOFTQ
SOFTQ system
PLP
The value for this option must be one of these seven selections. For example:
printing = SYSV
The default value of this option is system-dependent and is configured when Samba is first compiled. For
most systems, the configure script automatically detects the printing system to be used and configures it
properly in the Samba makefile. However, if your system is a PLP, LPRNG, or QNX printing system, you
need to specify this explicitly in the makefile or the printing share.
The most common system types are BSD, SYSV, and CUPS. Each printer on a BSD Unix server is
described in the printer capabilities filenormally /etc/printcap. See the section on the printcapfile
parameter for more information on this topic.
Setting the printing configuration option automatically sets at least three other printing options for the
service in question: printcommand,lpqcommand, and lprmcommand. If you are running Samba on a
system that doesn't support any of the printing styles listed in Table 10-3, simply set the commands for
each of these manually.
10.2.3.2 printable
Theprintable option must be set to yes to flag a share as a printing service. If this option is not set, the
share will be treated as a disk share instead. You can set the option as follows:
[printer1]
printable = yes
10.2.3.3 printer
The option, also called printername, specifies the name of the printer on the server to which the share
points. This option has no default and should be set explicitly in the configuration file, even though Unix
systems
themselves
recognize a default name such as lp for a printer. For example:
Table of often
Contents
Index
Reviews
[deskjet]
Reader Reviews
printer = hpdkjet1
Errata
10.2.3.4
lpq cache time
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The global lpqcachetime option allows you to set the number of seconds for which Samba will
Publisher: O'Reilly
remember the current printer status. After this time elapses, Samba will issue an lpq command (or
Pub Date: February 2003
whatever
command you specify with the lpqcommand option) to get a more up-to-date status that it can
0-596-00256-4
report ISBN:
to users.
This defaults to 10 seconds, but can be increased if your lpqcommand takes an unusually
Pages:
556
long time to run or you have lots of clients. A time setting of 0 disables caching of queue status. The
Slots:
1
following
example
resets the time to 30 seconds:
[deskjet]
cacheSecond
time =
30 is a comprehensive guide to Samba administration. This new edition covers
Usinglpq
Samba,
Edition
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWATpostscript
graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
10.2.3.5
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
and to
filesystem
security
Unix system,
and
accessing
The
postscript
option authentication
forces the printer
treat all data
senton
to the
it ashost
PostScript.
It does
this
by prefixing
shared
files and%!printers
from Unix of
clients.
the
characters
to the beginning
the first line of each job. It is normally used with PCs that insert a
^D (control-D or "end-of-file" mark) in front of the first line of a PostScript file. It will not, obviously, turn
a non-PostScript printer into a PostScript one. The default value of this options is no. You can override it
as follows:
[deskjet]
postscript = yes
We have placed annotated comments off to the right in case you've never dealt with this file before.
lp:\
:sd=/var/spool/lpd/lp:\
spool directory
:mx#0:\
:sh:\
:lp=/dev/lp1:\
:if=/var/spool/lpd/lp/filter:
text filter
laser:\
:sd=/var/spool/lpd/laser:\
spool directory
:mx#0:\
:sh:\
:lp=/dev/laser:\
Table of Contents
Index
:if=/var/spool/lpd/lp/filter:
Reviews
Reader
the shares [lp]
and Reviews
[laser] are automatically created as valid print shares when Samba is started. Both
Errata
shares borrow the configuration options specified in the [printers] section to configure themselves and
Using
Samba, 2nd
Edition
are available
in the
browse
list for the Samba server. The default value for this option is yes. If you prefer
to
specify
each printer
explicitly
your
ByDavid
Collier-Brown
, Robert
Ecksteinin
, Jay
Ts configuration file, use the following:
[global]
Publisher: O'Reilly
Pub
Date:printers
February 2003
load
=
no
ISBN: 0-596-00256-4
Pages: 556
10.2.3.7
print command, lpq command, lprm command,lppause command, lpresume
Slots: 1
command
These options tell Samba which Unix commands control and send data to the printer. The Unix
commands
involved
are:
lpr (send
to Line PRinter),
lpq (List
Printeradministration.
Queue), lprm (Line
Printer
ReMove),
Using Samba,
Second
Edition
is a comprehensive
guide
to Samba
This new
edition
covers
and
optionally
lppause
and
lpresume.
Samba
provides
an
option
named
after
each
command,
in
case
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as
wellyou
as
need
to override
anyconfiguration
of the system
defaults.
Forfor
example,
consider
the following:
the SWAT
graphical
tool.
Updated
Windows
2000, ME,
and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
lpq command = /usr/ucb/lpq %p
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
filesset
andlpq
printers
from
Unix/usr/ucb/lpq.
clients.
This
would
command
to use
Similarly:
lprm command = /usr/local/bin/lprm -P%p %j
would set the Samba printer remove command to /usr/local/bin/lprm and provide it the print job number
using the %j variable.
The default values for each option are dependent on the value of the printing option. Table 10-4 shows
the default commands for each printing option. The most popular printing system is BSD.
SYSV, HPUX
QNX
SOFTQ
printcommand
lpr -r -P%p %s
lp -c -d%p %s; rm
%s
lp -r -P%p
%s
lp -d%p -s %s; rm
%s
lpqcommand
lpq -P%p
lpstat -o%p
lpq -P%p
lpstat -o%p
lprmcommand
lprm -P%p %j
cancel %p-%j
None
None
None
None
None
qstat -s -j%j -r
lp -i %p-%j -Hhold
lppausecommand
(SYSV only)
lpresume
command
lp -i %p-%j -H
resume
(SYSV only)
It is usually unnecessary to reset these options in Samba, with the possible exception of the print
command. This option might need to be set explicitly if your printing system doesn't have a -r (remove
after printing) option on the printing command. For example:
print command = /usr/local/lpr -P%p %s; /bin/rm %s
With a bit of judicious programming, these smb.conf options can also be used for debugging:
print
command
= cat
%s >>/tmp/printlog; lpr -r -P%p %s
Table
of Contents
Index
Reader Reviews
Using the previous configuration, it is possible to verify that files are actually being delivered to the
Reviews
Samba server. If they are, their contents will show up in the file /tmp/printlog.
ISBN: 0-596-00256-4
lp|print1|My
Printer 1
Pages: 556
print2|My
Slots: 1
Printer 2
print3|My Printer 3
Each
names
a printer
followed
by aliases for it.
In this
example,
the first printer
is called
lp,print1,
Usingline
Samba,
Second
Edition
is a comprehensive
guide
to Samba
administration.
This
new edition
covers
or
My
Printer
1,
whichever
the
user
prefers
to
use.
The
first
name
is
used
in
place
of
%p
in
any
command
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0,
as well as
Samba
executes
for configuration
that printer. tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
graphical
Samba's new role as a primary domain controller and domain member server, its support for the use of
Two additional printer types are also supported by Samba: LPRNG (LPR New Generation) and PLP (Public
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Line Printer). These are public domain and open source printing systems and are used by many sites to
shared files and printers from Unix clients.
overcome problems with vendor-supplied software. Samba also supports the printing systems of the
SOFTQ and QNX real-time operating systems.
[deskjet]
min print space = 4000
Table
of Contents
not need to alter
this
option.
Index
Reviews
Reader Reviews
10.2.3.11 queueresume
command
Errata
This configuration option specifies a command that tells Samba how to resume a paused print queue, as
By
David Collier-Brown
, Robert
Eckstein
opposed
to resuming
a single
job,Jay
onTs
the print queue. The default value depends on the printing type
chosen. You should not need to alter this option.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
only in isolated circumstances.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of modified
Contents the user's profile.
Index
Errata
Time
synchronization
Reviews can also be very important to programmers. A useful group of settings consists of
the
following
options:
Reader Reviews
[global]
dos filetimes
Publisher:
O'Reilly
= yes
Pages: 556
1. Run NTP on the Unix systems in your network. For more information on using NTP, refer to
http://www.ntp.org.
2. Use one of the Unix systems (such as the Samba host system) as an NTP server to serve Windows
2000/XP clients.
3. For other Windows clients, you might have to download an update from Microsoft to add Windows
Time Service client support or use a third-party application such as the free analogX Atomic
Table
of Contents
TimeSync
(http://www.analogx.com).
Or you can use the net time command to update the client's
Index
clock periodically,
as discussed previously.
Reviews
Reader Reviews
Errata
11.1.1 Time-Synchronization
Options
Using Samba, 2nd Edition
By
Collier-Brown
Eckstein
, Jay Ts
ToDavid
support
roaming,Robert
profiles,
programmers
Option
Parameters
Function
Default Scope
no
Share
Boolean
no
Share
resolution
fake directory
create times
Traditionally, only the root user and the owner of a file can change its last-modified date on a Unix
system. The share-level dosfiletimes option allows the Samba server to mimic the characteristics of a
DOS or Windows system: any user can change the last-modified date on a file in that share if she has
write permission to it. To do this, Samba uses its root privileges to modify the timestamp on the file.
By default, this option is disabled. Setting this option to yes is often necessary to allow PC make
programs to work properly. Without it, they cannot change the last-modified date themselves. This often
results in the program thinking all files need recompiling when they really don't.
Table of Contents
Index
11.1.1.4
dosReviews
filetime resolution
Reader Reviews
Errata
Thedosfiletime
resolution parameter is a share-level option. If set to yes, Samba rounds file times
Using Samba, 2nd Edition
to the closest 2-second boundary. This option exists primarily to satisfy a quirk in Windows that prevents
By
DavidC++
Collier-Brown
, Robert Eckstein
, Jay Ts that a file has not changed. You can enable it as follows:
Visual
from correctly
recognizing
[data]
Publisher: O'Reilly
Pub Date: February 2003
Pages: 556
recommend
We
using this option only if you are using Microsoft Visual C++ on a Samba share that
Slots:
1
supports
opportunistic
locking.
Table of Contents
Index
Reviews
Reader
ReviewsOptions
11.2.1 Magic
Script
Errata
Table 11-2 lists the options that deal with magic scripts on the Samba server.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Option
Slots: 1
magic
script
Parameters
string
(filename)
Function
File to be executed by Samba, as the logged-on
user, when closed
Default
None
Scope
Share
magicSamba, string
Using
Second Edition isFile
a comprehensive
guide
to magic
Sambafile
administration. scriptname.out
This new edition Share
covers
to log output from
the
output
all
versions of (filename)
Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
11.2.1.1
magic script
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
If the magicscript option is set to a filename and the client creates a file by that name in that share,
Samba will run the file as soon as the user has opened and closed it. For example, let's assume that the
following option was created in the share [accounting]:
[accounting]
magic script = tally.sh
Samba continually monitors the files in that share. If one by the name of tally.sh is closed (after being
opened) by a user, Samba will execute the contents of that file locally. The file will be passed to the shell
to execute; it must therefore be a legal Unix shell script. This means that it must have newline characters
as line endings instead of Windows CRLFs. In addition, you need to use the #! directive at the beginning
of the file to indicate under which shell or interpreter the script should run, unless the script is for the
default shell on your system.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
11.3 Internationalization
Starting with Samba 3.0, Samba supports Unicode "on the wire," requiring no additional effort on your
part to support filenames and other text containing characters in international character sets.
Table of Contents
Index
11.3.1 Internationalization
Options
Reviews
Reader Reviews
Samba 2.2.x has a limited ability to speak foreign tongues: if you need to support filenames containing
Errata
characters that
aren't in standard ASCII, some options that can help you are shown in Table 11-3.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Option
Pages: 556
Slots: 1
client
code
page
Parameters
Described in this
section
Function
Sets a code page to expect from clients
Default Scope
850
Global
Described in this
Translates code pages into alternate Unix
character set
None
Global
section
character
setsto Samba administration. This new edition covers
Using Samba, Second
Edition is a comprehensive
guide
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Described in this
Translates code page 932 into an Asian
coding
Global
the
SWATsystem
graphical configuration tool. Updated for Windows 2000, ME, and XP, the bookNone
also explores
section
character set
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP
authentication
and filesystem security on the host Unix system, and accessing
string
(set of
valid chars
Adds individual characters to a code page
None
Global
shared files and printers
from Unix clients.
characters)
Code page
Definition
437
737
Windows 95 Greek
850
852
861
MS-DOS Icelandic
Table of Contents
866
Index
Reviews
932
936
Errata
949
950
Publisher: O'Reilly
Date:
2003code page as follows:
YouPub
can
setFebruary
the client
ISBN: 0-596-00256-4
[global]
Pages: 556
Slots: 1
Definition
ISO8859-1
850
ISO8859-2
852
ISO8859-5
866
ISO8859-7
737
Greek Unix
KOI8-R
866
Table of Contents
that Samba accepts are listed in Table 11-6.
Index
Reviews
Reader Reviews
Errata
Character set
Publisher: O'Reilly
SJIS
Definition
Standard Shift JIS
JIS8
J8BB
ISBN: 0-596-00256-4
Eight-bit
Pages: 556
Slots: 1
JIS codes
J8BH
J8@B
Using
EditionJIS
is acodes
comprehensive guide to Samba administration. This new edition covers
J8@J Samba, Second
Eight-bit
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
J8@H
JIS codes
the
SWAT graphicalEight-bit
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new
role
as
a
primary
domain
JIS7
Seven-bit JIS codes controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
J7BB files and printers
shared
Seven-bit
from JIS
Unix
codes
clients.
J7BH
J7@B
J7@J
J7@H
JUNET
JUNET codes
JUBB
JUNET codes
JUBH
JUNET codes
JU@B
JUNET codes
JU@J
JUNET codes
JU@H
JUNET codes
EUC
EUC codes
HEX
CAP
of Contents
character.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
Windows Messenger
Reviews
Reader Reviews
TheWinPopup tool (Winpopup.exe), shown in Figure 11-1, can be used on Windows 95/98/Me to send or
Errata
receive messages. WinPopup is a handy tool for sending messages. However, to receive messages, it
Using Samba, 2nd Edition
must already be running when the message is sent from the remote system.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
On Windows NT/2000/XP, the messenger service lets you receive messages without having an application
already running; messages will automatically appear in a small dialog box on the screen when received,
as shown in Figure 11-2.
To send messages, it is necessary to use the net send command from a command-prompt window, like
this:
C:\>net send maya "Who's There?"
The message was successfully sent to MAYA.
string (shell
command)
message
command
11.4.1.1
Parameter
Function
Sets a command to run on Unix when a
WinPopup message is received
Default Scope
None
Global
Table ofcommand
Contents
message
Index
Reviews
Samba'smessage
command option defines the command that will run on the server when a Windows
Readermessage
Reviews arrives. The command will be executed as the guestaccount user. What to
Messenger Service
Errata
do with messages is questionable because most Samba hosts run as unattended servers. One solution is
Using
Samba,
2nd Editionto
to mail
the messages
[global]
Publisher: O'Reilly
In addition to the standard variables, Table 11-8 shows the three unique variables that you can use in a
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
messagecommand.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Variable
Definition
%s
%f
%t
Table of Contents
Index
Reviews
Reader Reviews
Errata
Parameters
ByDavidOption
Collier-Brown, Robert
Eckstein, Jay Ts
deadtime
Publisher: O'Reilly
numeric
(minutes)
string
0-596-00256-4
dfreeISBN:
command
(command)
Pages: 556
Slots: 1
fstype
NTFS,FAT, or
Samba
Function
Default
Scope
Global
None
Global
NTFS
Global
300
numeric
Number of seconds between checks for an
keepalive
Global
(seconds)
inoperative client.
(none)
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, Largest
including
disk
selected
size tofeatures
return tofrom
a client,
an alpha
some
version
of
of 3.0, as well as
maxSWAT
disk graphical
size
0 (infinity)
the
configuration
numeric (MB)
tool.which
Updated
have
forlimits.
Windows
Does2000,
not affect
ME, and
actual
XP, the book
also explores
Global
Samba's new role as a primary domainoperations
controller on
andthe
domain
disk. member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Maximum number of simultaneous SMB
shared
files and printers
from Unix clients.
max mux
50
numeric
Global
operations that clients can make.
max open files
numeric
10000
Global
max xmit
numeric
65535 or
16644
Global
nt pipe support
Boolean
yes
Global
nt smb support
Boolean
yes
Global
ole locking
compatibility
Boolean
yes
Global
panic action
string
None
Global
set directory
Boolean
no
Global
status
Boolean
yes
Global
strict sync
Boolean
no
Global
sync always
Boolean
no
Global
strip dot
Boolean
no
Global
change notify
timeout
numeric
(seconds)
60
Global
stat cache
Boolean
yes
Global
numeric
50
Global
11.5.1
deadtime
Table of Contents
Index
Reviews
session with the
Samba
server. A client is considered inactive when it has no open files and no data is
Reader
Reviews
being sent from
it. The default value for this option is 0, which means that Samba never closes any
Errata
connection,
Using
Samba, regardless
2nd Edition of how long they have been inactive. This can lead to unnecessary consumption of
the server's resources by inactive clients. We recommend that you override the default as follows:
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
[global]
Publisher: O'Reilly
deadtime
= 10
Pub
Date: February
2003
ISBN: 0-596-00256-4
This tells Samba to terminate any inactive client sessions after 10 minutes. For most networks, setting
Pages: 556
this option as such will not inconvenience users because reconnections from the client are generally
Slots: 1
performed
transparently to the user. See also the keepalive parameter.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
This
globalgraphical
option is configuration
used on systems
incorrectly
determine
theME,
freeand
space
thealso
disk.explores
So far,
the SWAT
tool.that
Updated
for Windows
2000,
XP,left
theon
book
the
only
confirmed
system
that
needs
this
option
set
is
Ultrix.
There
is
no
default
value
for
this
option,
Samba's new role as a primary domain controller and domain member server, its support for the use of
which
means
that Samba
already knows
to compute
theon
free
disk
space
its own
and
the results
Windows
NT/2000/XP
authentication
and how
filesystem
security
the
host
Unixon
system,
and
accessing
are
considered
reliable.
You
can
override
it
as
follows:
shared files and printers from Unix clients.
[global]
dfree command = /usr/local/bin/dfree
This option should point to a script that returns the total disk space in a block and the number of
available blocks. The Samba documentation recommends the following as a usable script:
#!/bin/sh
df $1 | tail -1 | awk '{print $2" "$4}'
On System V machines, the following will work:
#!/bin/sh
/usr/bin/df $1 | tail -1 | awk '{print $3" "$5}'
11.5.1.2 fstype
This share-level option sets the type of filesystem that Samba reports when queried by the client. Three
strings can be used as a value to this configuration option, as listed in Table 11-10.
Value
Definition
NTFS
FAT
Index
Reviews
Reader Reviews
[data]
fstype =Errata
FAT
11.5.1.3 keepalive
Publisher: O'Reilly
This global option specifies the number of seconds that Samba waits between sending NetBIOS keepalive
Pub Date:
February
2003 are used to ping a client to detect whether it is still alive and on the network. The
packets.
These
packets
0-596-00256-4
defaultISBN:
value
for this option is 300 (5 minutes), which you can override as follows:
Pages: 556
[global]
Slots: 1
keepalive = 600
The value of 600 (10 minutes) is good for networks populated by reliable clients. If your network contains
Using
Samba,
Second
Edition
is a
comprehensive
guide
to Samba
Thisas
new
covers
relatively
unreliable
clients,
you
might
prefer to set
keepalive
to aadministration.
lower value, such
30.edition
If keepalive
all
versions
of
Samba
from
2.0
to
2.2,
including
selected
features
from
an
alpha
version
of
3.0,
as
well
as
is set to 0, no NetBIOS keepalive packets will be sent. See also the deadtime parameter.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
11.5.1.4
max
sizefrom Unix clients.
shared files
anddisk
printers
This global option specifies an illusory limit, in megabytes, for each share that Samba is offering. It only
affects how much disk space Samba reports the share as having and does not prevent more disk space
from actually being available for use. You would typically set this option to prevent clients with older
operating systemsor running buggy applicationsfrom being confused by large disk spaces. For
example, some older Windows applications become confused when they encounter a share larger than 1
gigabyte. To work around this problem, maxdisksize can be set as follows:
[global]
max disk size = 1000
The default value for this option is 0, which means there is no upper limit.
[global]
max open files = 8000
Table
of Contentspacket size can increase performance, especially with Windows for
Workgroups. In Samba versions up to 2.2.5, the default value for this option is 65535. In 2.2.7 and later
Index
versions, the default was changed to 16644 to match the behavior of Windows 2000 and improve support
Reviews
for Windows NT 4.0. You can override the default as follows:
Reader Reviews
[global]
Errata
maxCollier-Brown
xmit = 4096
ByDavid
, Robert Eckstein, Jay Ts
Publisher:
11.5.1.8
ntO'Reilly
pipe support
Pub Date: February 2003
ISBN: option
0-596-00256-4
This global
is used by developers to allow or disallow Windows NT/2000/XP clients the ability to
make Pages:
connections
556
to NT-specific SMB IPC$ pipes. As a user, you should never need to override the
default:
Slots: 1
[global]
nt pipe support = yes
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
11.5.1.9
smb support
the SWATnt
graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
andto
filesystem
on the
host
Unix with
system,
and accessing
This
global
option is used
by developers
negotiatesecurity
NT-specific
SMB
options
Windows
NT/2000/XP
shared files
and printers
Unix clients.
clients.
The Samba
Teamfrom
has discovered
that slightly better performance comes from setting this value
tono. However, as a user, you should probably not override the default:
[global]
nt smb support = yes
This Boolean share-level option allows Digital Pathworks clients to use the setdir command to change
directories on the server. If you are not using the Digital Pathworks client, you should not need to alter
this option. The default value for this option is no. You can override it per share as follows:
[data]
set directory = yes
Table of Contents
11.5.1.13 status
Index
Reviews
This global option indicates whether Samba should log all active connections to a status file. This file is
Reader Reviews
used only by the smbstatus command. If you have no intentions of using this command, you can set this
Errata can result in a small increase of speed on the server. The default value for this option
option to no, which
Using
Samba,
2nd
Edition it as follows:
is yes. You can override
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
[global]
Publisher: O'Reilly
status = no
11.5.1.14
sync
Pages:strict
556
Slots: 1
This share-level option determines whether Samba honors all requests to perform a disk sync when
requested to do so by a client. Many Windows clients request a disk sync when they are really just trying
to flush data to their own open files. In this case, a disk sync is generally unnecessary on Unix due to its
high reliability, and it mostly has the effect of substantially reducing the performance of the Samba host
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
system. The default value for this option is no, which allows the superfluous disk sync requests to be
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
ignored. You can override the default as follows:
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
[data] new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and
printers
strict
sync
= yes from Unix clients.
Performing these checks too often can slow down the server considerably; however, you can use this
option to specify an alternate time that Samba should wait between performing checks:
[global]
change notify timeout = 30
Table of Contents
Reviews
Reader Reviews
Errata
The
statcacheIndex
global option turns on caching of recent case-insensitive name mappings. The default is
yes. The Samba Team recommends that you never change this parameter.
11.5.1.19
stat
Using Samba,
2nd cache
Edition size
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Thestatcachesize global option sets the number of cache entries to be used for the statcache
option. The default here is 50. Again, the Samba Team recommends that you never change this
Publisher: O'Reilly
parameter.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
While we can't describe in detail the solution to every problem you might encounter, you should be able
Reviews
Reader
Reviews
The first section
of this
chapter lists the tool bag, a collection of tools available for troubleshooting
Errata
Samba; the second section is a detailed how-to; the last section lists extra resources to track down
Using Samba, stubborn
2nd Edition
particularly
problems.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Samba logs
Reviews
Reader Reviews
Samba test
utilities
Errata
Using Unix
Samba,
2nd Edition
utilities
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Fault tree
Publisher: O'Reilly
Samba
ISBN: 0-596-00256-4
newsgroups
Pages: 556
Searchable
mailing list archives
Slots: 1
Let's go over each of these one-by-one in the following sections.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
12.1.1
Samba
Logs
all versions
of Samba
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Your
first new
line role
of attack
should always
becontroller
to check and
the log
files.member
The Samba
log files
can help
the
Samba's
as a primary
domain
domain
server,
its support
fordiagnose
the use of
vast
majority
of the problems
faced by
beginningintermediate-level
administrators.
Samba is
Windows
NT/2000/XP
authentication
and
filesystemtosecurity
on the hostSamba
Unix system,
and accessing
quite
flexible
when
it comes
toUnix
logging.
You can set up the server to log as little or as much information
shared
files and
printers
from
clients.
as you want. Using substitution variables in the Samba configuration file allows you to isolate individual
logs for each system, share, or combination thereof.
Logs are placed in /usr/local/samba/var/smbd.log and /usr/local/samba/var/nmbd.log by default. You
can specify a log directory to use with the -l flag on the command line when starting the Samba
daemons. For example:
#smbd -l /var/log/samba
#nmbd -l /var/log/samba
Alternatively, you can override the location and name using the logfile configuration option in
smb.conf. This option accepts all the substitution variables, so you could easily have the server keep a
separate log for each connecting client system by specifying the following:
[global]
log file = %m.log
Another useful trick is to have the server keep a log for each service (share) that is offered, especially if
you suspect a particular share is causing trouble. To do this, use the %S variable, like this:
[global]
log file = %S.log
no logging is done. Higher values result in more voluminous logging. For example, let's assume that we
will use a Windows client to browse a directory on a Samba server. For a small amount of log
information, you can use loglevel=1, which instructs Samba to show only cursory information, in this
case only the connection itself:
05/25/02 22:02:11 server (192.168.236.86) connect to service public as user pcguest
(uid=503,gid=100) (pid 3377)
Higher debug Table
levelsofproduce
Contents more detailed information. Usually, you won't need more than level 3, which
is fully adequate
for most Samba administrators. Levels above 3 are used by the developers and dump
Index
enormous amounts
Reader Reviews
Here
is an example
of output at levels 2 and 3 for the same operation. Don't worry if you don't
Errata
understand
the
intricacies
of an SMB connection; the point is simply to show you what types of
Using Samba, 2nd Edition
information are shown at the different logging levels:
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
/* Level 2 */
Publisher: O'Reilly
GotPub
SIGHUP
Date: February
2003
ISBN: 0-596-00256-4
Slots: 1
Processing
section "[public]"
/* Level 3 */
05/25/02 22:15:09 Transaction 63 of length 67
switch message SMBtconX (pid 3377)
Allowed connection from 192.168.236.86 (192.168.236.86) to IPC$
ACCEPTED: guest account and guest ok
found free connection number 105
Connect path is /tmp
chdir to /tmp
chdir to /
05/25/02 22:15:09 server (192.168.236.86) connect to service IPC$ as user pcguest
(uid=503,gid=100) (pid 3377)
05/25/02 22:15:09 tconX service=ipc$ user=pcguest cnum=105
05/25/02 22:15:09 Transaction 64 of length 99
switch message SMBtrans (pid 3377)
chdir to /tmp
trans <\PIPE\LANMAN> data=0 params=19 setup=0
Got API command 0 of form <WrLeh> <B13BWz> (tdscnt=0,tpscnt=19,mdrcnt=4096,mprcnt=8)
Doing RNetShareEnum
RNetShareEnum gave 4 entries of 4 (1 4096 126 4096)
Table of Contents
Index
05/25/02
22:15:11
Transaction 65 of length 99
Reviews
switch
message
Reader
SMBtrans
Reviews (pid 3377)
Errata
chdir
to / 2nd Edition
Using Samba,
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
chdir to /tmp
Publisher: O'Reilly
trans
<\PIPE\LANMAN> data=0 params=19 setup=0
Pub Date: February 2003
ISBN:
0-596-00256-4
Got API
command
0 of form <WrLeh> <B13BWz> (tdscnt=0,tpscnt=19,mdrcnt=4096,mprcnt=8)
Pages: 556
Doing Slots:
RNetShareEnum
1
RNetShareEnum gave 4 entries of 4 (1 4096 126 4096)
05/25/02
22:15:11
66 of length guide
95
Using Samba,
SecondTransaction
Edition is a comprehensive
to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
switch
message
SMBtrans2
(pidtool.
3377)
the SWAT
graphical
configuration
Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
chdir
to NT/2000/XP
/
Windows
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
chdir to /pcdisk/public
call_trans2findfirst: dirtype = 0, maxentries = 6, close_after_first=0, close_if_end
= 0 requires_resume_key = 0 level = 260, max_data_bytes = 2432
unix_clean_name [./DESKTOP.INI]
unix_clean_name [desktop.ini]
unix_clean_name [./]
creating new dirptr 1 for path ./, expect_close = 1
05/25/02 22:15:11 Transaction 67 of length 53
switch message SMBgetatr (pid 3377)
chdir to /
produce massive amounts of data. Essentially, you should turn on logging level 3 only when you're
actively tracking a problem in the Samba server.
of Contents
one
while
it's
running,
like this:
Index
Reviews
Reader Reviews
or a SIGUSR2Errata
signal to decrease it by one:
Using Samba, 2nd Edition
#
1234
Bykill
David -SIGUSR2
Collier-Brown
, Robert Eckstein, Jay Ts
12.1.1.3
Logging
by individual client systems or users
Publisher:
O'Reilly
Pub Date: February 2003
An effective
way to diagnose problems without hampering other users is to assign different log levels for
ISBN: 0-596-00256-4
different
systems
in the [global] section of the smb.conf file. We can do this by building on the strategy
Pages:
556
we presented
earlier:
Slots: 1
[global]
log level = 0
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
log file
= /usr/local/samba/var/log.%m
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role
as a primary domain controller and domain member server, its support for the use of
include
= /usr/local/samba/lib/smb.conf.%m
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
sharedoptions
files and
printers
from Unix
clients.
These
instruct
Samba
to use
unique configuration and log files for each client that connects. Now
all you have to do is create an smb.conf file for a specific client system with a loglevel=3 entry in it
(the others will pick up the default log level of 0) and use that log file to track down the problem.
Similarly, if only particular users are experiencing a problemand it travels from system to system with
themyou can isolate logging to a specific user by adding the following to the smb.conf file:
[global]
log level = 0
log file = /usr/local/samba/var/log.%u
include = /usr/local/samba/lib/smb.conf.%u
Then you can create a unique smb.conf file for each user you wish to monitor (e.g.,
/usr/local/samba/lib/smb.conf.tim ). Files containing the configuration option loglevel=3 and only
those users will get more detailed logging.
Table of Contents
Index masquerades under several different names, depending on the operating system you
Thetrace command
Reviews
will have traceReader
or tusc.
All have essentially the same function, which is to display each operating system
Errata
function call as it is executed. This allows you to follow the execution of a program, such as the Samba
Using
Samba,
2nd Edition
server,
and often
pinpoints
One problem that trace can highlight is an incorrect version of a dynamically linked library. This can
happen if you've downloaded prebuilt binaries of Samba. You'll typically see the offending call at the end
Publisher: O'Reilly
of the trace, just before the program terminates.
Pub Date: February 2003
ISBN:
0-596-00256-4
A sample
strace
output for the Linux operating system follows. This is a small section of a larger file
created
during
Pages:
556 the opening of a directory on the Samba server. Each line lists a system call and includes
its parameters
and the return value. If there was an error, the error value (e.g., ENOENT) and its
Slots: 1
explanation are also shown. You can look up the parameter types and the errors that can occur in the
appropriatetrace manual page for the operating system you are using.
chdir("/pcdisk/public")
= 0
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions of Samba from 2.0
to 2.2, including= selected
features
from an
alpha
of 3.0, as well as
stat("mini/desktop.ini",
0xbffff7ec)
-1 ENOENT
(No such
file
or version
directory)
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role
as a primary domain controller
and domain
member
stat("mini",
{st_mode=S_IFDIR|0755,
st_size=1024,
...})
= 0 server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and printers from0xbffff7ec)
Unix clients.
stat("mini/desktop.ini",
= -1 ENOENT (No such file or directory)
open("mini", O_RDONLY)
= 5
= 0
= 0
= 1024
= 0
stat("mini/desktop.ini", 0xbffff86c)
= 4
= 896143871
This example shows several stat() calls failing to find the files they were expecting. You don't have to be
an expert to see that the file desktop.ini is missing from that directory. In fact, many difficult problems
can be identified by looking for obvious, repeatable errors with trace. Often, you need not look further
than the last message before a crash.
of Contents
type
of
traffic.
You
can
examine
all conversations between client and server, including SMB and NMB
Index
broadcast
messages.
While
its
troubleshooting
capabilities lie mainly at the OSI network layer, you can
Reviews
still use its output to get a general idea of what the server and client are attempting to do.
Reader Reviews
Errata
A sample tcpdump
log follows. In this instance, the client has requested a directory listing, and the server
Using
Samba,
2nd
Edition
has responded appropriately,
giving the directory names homes,public,IPC$, and temp (we've added a
By
David
Collier-Brown
, Robert
Eckstein, Jay Ts
few
explanations
on
the right):
$tcpdump
-v -s 255 -i eth0 port not telnet
Publisher: O'Reilly
Pub Date: February 2003
Pages: 556
SMB Command
=
0x25
Request packet
Request was ls or dir
Slots: 1
[000] 01 00 00 10
....
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
and printers from Unix clients.
>>>
NBTfiles
Packet
Outer frame of SMB packet
NBT Session Packet
Flags=0x0
Length=226
[lines skipped]
Beginning of a reply to
SMB Command
0x25
Error class
0x0
Error code
Flags1
0x80
Flags2
0x1
Tree ID
105
Proc ID
6075
UID
100
MID
30337
No errors
request
Word Count
10
TotParamCnt=8
TotDataCnt=163
Res1=0
ParamCnt=8
Table of Contents
Index
ParamOff=55
Reviews
Reader Reviews
Errata
Res2=0
DataCnt=163
DataOff=63
Publisher: O'Reilly
Res3=0
Pub Date: February
2003
ISBN: 0-596-00256-4
Lsetup=0
Pages: 556
Slots: 1
........
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
graphical
configuration tool. Updated for Windows
ME, andcontents:
XP, the book also explores
DataSWAT
Data:
(135 bytes)
Actual2000,
directory
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
authentication
and00filesystem
host Unix
system, and accessing
[000] 68 NT/2000/XP
6F 6D 65 73
00 00 00 00
00 00 00security
00 00 on
00 the
homes...
........
shared files and printers from Unix clients.
[010] 64 00 00 00 70 75 62 6C
69 63 00 00 00 00 00 00
d...publ ic......
[020] 00 00 00 00 75 00 00 00
74 65 6D 70 00 00 00 00
....u... temp....
[030] 00 00 00 00 00 00 00 00
76 00 00 00 49 50 43 24
........ v...IPC$
[040] 00 00 00 00 00 00 00 00
00 00 03 00 77 00 00 00
........ ....w...
[050] 64 6F 6E 68 61 6D 00 00
00 00 00 00 00 00 00 00
donham.. ........
[060] 92 00 00 00 48 6F 6D 65
20 44 69 72 65 63 74 6F
....Home
[070] 72 69 65 73 00 00 00 49
50 43 20 53 65 72 76 69
ries...I PC Servi
[080] 63 65 20 28 53 61 6D
Directo
ce (Sam
This is more of the same debugging session as we saw before with the trace command: the listing of a
directory. The options we used were -v (verbose), -i eth0 to tell tcpdump on which interface to listen (an
Ethernet port), and -s 255 to tell it to save the first 255 bytes of each packet instead of the default: the
first 68. The option portnottelnet is used to avoid screens of telnet traffic, because we were logged in
to the server remotely. The tcpdump program actually has quite a number of options to filter just the
traffic you want to look at. If you've used snoop or etherdump, it will look vaguely familiar.
You can download the modified tcpdump from the Samba FTP server, located at
ftp://samba.anu.edu.au/pub/samba/tcpdump-smb. Other versions might not include support for the SMB
protocol; if you don't see output such as that shown in the example, you'll need to use the SMB-enabled
version.
Ethereal (http://www.ethereal.com) is a GUI-based utility that performs the same basic function as
tcpdump. You might prefer Ethereal because it is much easier to use. Once you have Ethereal running,
just do the following:
1. Select Start from the Capture menu.
2. Click the OK button in the dialog box that appears. This will bring up a dialog box showing how
many packets
Table ofEthereal
Contents has seen. Perform the actions on the system(s) in your network to
reproduce
the
problem
you are analyzing.
Index
Reviews
3. Click the Stop button in the Ethereal dialog box to make it finish collecting data.
Reader Reviews
4. In the main
Errata
Ethereal window, click any item in the upper window to view it in the lower window. In
Using the
Samba,
2ndwindow,
Edition
lower
click any of the boxes containing a plus sign (+) to expand the view.
Ethereal does a good job of translating the content of the packets it encounters into human-readable
format, and you should have little trouble seeing what happened on the network during the capture
Publisher: O'Reilly
period.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Before
you setIndex
out to troubleshoot any part of the Samba suite, you should know the following
information:
Reviews
Reader Reviews
Errata
Your client
IP address (we use 192.168.236.10)
Your
server IP,Robert
address
(we,Jay
useTs192.168.236.86)
ByDavid
Collier-Brown
Eckstein
The netmask for your network (typically 255.255.255.0)
Publisher: O'Reilly
Pub
Date: February
2003
Whether
the systems
ISBN: 0-596-00256-4
For clarity,
renamed the server in the following examples to server.example.com, and the client
Pages: we've
556
systemSlots:
to client.example.com.
1
Table of Contents
packets transmitted,
Index
3
3 packets received, 0% packet loss round-trip (ms)
Reviews
min/avg/max
Reader
= 0/0/1
Reviews
Errata
If youSamba,
get "ping:
no answer from . . . " or "100% packet loss," you have no IP networking installed on the
Using
2nd Edition
system. The address 127.0.0.1 is the internal loopback address and doesn't depend on the computer
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
being physically connected to a network. If this test fails, you have a serious local problem. TCP/IP either
isn't installed or is seriously misconfigured. See your operating system documentation if it's a Unix
Publisher:
O'Reilly
server.
If it's
a Windows client, follow the instructions in Chapter 3 to install networking support.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Ifyou're the network manager, some good references are Craig Hunt's TCP/IP
Network Administration, Chapter 11, and Craig Hunt and Robert Bruce Thompson's
Windows NT TCP/IP Network Administration, both published by O'Reilly.
12.2.2.2
Testing
local
name
with ping
Using Samba,
Second
Edition
is services
a comprehensive
guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
Updated
forThe
Windows
2000,hostname
ME, and XP,
theconventional
book also explores
Next,
try to
ping localhost
on thetool.
Samba
server.
localhost
is the
Samba's new
as a primary
domaininterface,
controllerand
anditdomain
server,
its support
fortyping
the use
of
hostname
for role
the 127.0.0.1
loopback
should member
resolve to
that address.
After
ping
Windows NT/2000/XP
and filesystem
security on the host Unix system, and accessing
localhost,
you shouldauthentication
see output similar
to the following:
shared files and printers from Unix clients.
$ ping localhost
PING localhost: 56 data bytes
icmp-seq=0. time=0. ms
icmp-seq=1. time=0. ms
icmp-seq=2. time=0. ms
^C
Table of Contents
packets transmitted,
Index
3
3 packets received, 0% packet loss round-trip (ms)
Reviews
min/avg/max
Reader
= 0/0/1
Reviews
Errata
If
thisSamba,
works2nd
on Edition
the server, repeat it for the client. Otherwise:
Using
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Ifpingnetwork_ip fails on either the server or client, but ping127.0.0.1 works on that system,
problem that is specific to the Ethernet network interface card on the computer.
Pub
Check
Date: February
with the
2003
documentation for the network card or host operating system to determine how to
configure
it correctly. However, be aware that on some operating systems, the ping command
ISBN: 0-596-00256-4
appears
Pages: 556to work even if the network is disconnected, so this test doesn't always diagnose all
hardware
problems.
Slots: 1
Publisher:
O'Reilly
you have
a TCP/IP
ping command reports on each system, and ensure that they match the ones you set up initially.
If not, there is at least one mismatched address between the two systems. Try entering the
commandarp-a, and see if there is an entry for the other system. (The arp command stands for
the Address Resolution Protocol. The arp-a command lists all the addresses known on the local
system.) Here are some things to try:
the IP
Publisher:IfO'Reilly
address from ARP doesn't match the addresses you expected, investigate and correct
the
addresses
manually.
Pub Date: February 2003
ISBN: 0-596-00256-4
If each system can ping itself but not another, something is wrong on the network between them.
Pages: 556
IfSlots:
you 1get ping:networkunreachable or ICMPHostUnreachable, you're not receiving an answer,
and more than one network is probably involved.
In principle, you shouldn't try to troubleshoot SMB clients and servers on different networks. Try to
a server
and Edition
client that
on the sameguide
network:
Usingtest
Samba,
Second
is a are
comprehensive
to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
configuration
Updated
for Windows
2000,
ME,inand
the book
also
explores
1. graphical
First, perform
the tests tool.
for ping:
noanswer
described
earlier
thisXP,
section.
If this
doesn't
Samba's new role as a primary domain controller and domain member server, its support for the use of
identify the problem, the remaining possibilities are the following: an address is wrong, your
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
netmask is wrong, a network is down, or the packets have been stopped by a firewall.
shared files and printers from Unix clients.
2. Check both the address and the netmasks on source and destination systems to see if
something is obviously wrong. Assuming both systems really are on the same network, they
both should have the same netmasks, and ping should report the correct addresses. If the
addresses are wrong, you'll need to correct them. If they are correct, the programs might be
confused by an incorrect netmask. See Section 12.2.8.1, later in this chapter.
3. If the commands are still reporting that the network is unreachable and neither of the previous
two conditions are in error, one network really might be unreachable from the other. This, too,
is an issue for the network manager.
If you get ICMPAdministrativelyProhibited, you've struck a firewall of some sort or a
misconfigured router. You will need to speak to your network security officer.
If you get ICMPHostredirect and ping reports packets getting through, this is generally harmless:
you're simply being rerouted over the network.
If you get a host redirect and no ping responses, you are being redirected, but no one is
responding. Treat this just like the Networkunreachable response, and check your addresses and
netmasks.
If you get ICMPHostUnreachablefromgatewaygatewayname, ping packets are being routed to
another network, but the other system isn't responding and the router is reporting the problem on
its behalf. Again, treat this like a Networkunreachable response, and start checking addresses and
netmasks.
If you get ping:unknownhosthostname, your system's name is not known. This tends to indicate a
name service problem, which didn't affect localhost. Have a look at Section 12.2.7, later in this
chapter.
If you get a partial successwith some pings failing but others succeedingyou have either an
intermittent problem between the systems or an overloaded network. Ping a bit longer, and see if
more than about three percent of the packets fail. If so, check it with your network manager: a
problem might just be starting. However, if only a few fail, or if you happen to know some massive
network program is running, don't worry unduly. The ICMP (and UDP) protocols used by ping are
allowed to drop occasional packets.
Index
Servers are
often multihomed i.e., connected to more than one network, with different names on
Reviews
each net.Reader
If youReviews
are getting a response from an unexpected name on a multihomed server, look at
the address
and see if it's on your network (see Section 12.2.8.1, later in this chapter). If so, you
Errata
useEdition
that address, rather than one on a different network, for both performance and reliability
Using should
Samba, 2nd
reasons.
Servers can also have multiple names for a single Ethernet address, especially if they are web
is harmless, albeit startling. You probably will want to use the official (and permanent)
name,
rather 2003
than an alias that might change.
Pub
Date: February
Publisher:
O'Reilly
servers.
This
ISBN: 0-596-00256-4
If everything works but the IP address reported is 127.0.0.1, you have a name service error. This
Pages: 556
typically occurs when an operating-system installation program generates an /etc/hosts line similar
1
toSlots:
127.0.0.1
localhosthostname.domainname. The localhost line should say 127.0.0.1
localhost or 127.0.0.1localhostloghost. Correct it, lest it cause failures to negotiate who is the
master browse list holder and who is the master browser. It can also cause (ambiguous) errors in
later tests.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all this
versions
of from
Samba
2.0 repeat
to 2.2, it
including
If
worked
thefrom
server,
from theselected
client. features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
12.2.3
Troubleshooting TCP
shared files and printers from Unix clients.
Now that you've tested IP, UDP, and a name service with ping, it's time to test TCP. Browsing and ping
use ICMP and UDP; file and print services (shares) use TCP. Both depend on IP as a lower layer, and all
four depend on name services. Testing TCP is most conveniently done using the FTP program.
If you received the message server:unknownhost, name service has failed. Go back to the
corresponding ping step, Section 12.2.2.2, and rerun those tests to see why name lookup failed.
If you received ftp:connect:Connectionrefused, the system isn't running an FTP daemon. This is
mildly unusual on Unix servers. Optionally, you might try this test by connecting to the system
usingtelnet instead of ftp; the messages are very similar, and telnet uses TCP as well.
If there was a long pause, and then ftp:connect:Connectiontimedout, the system isn't
reachable. Return to Section 12.2.2.4.
Table of Contents
If you received
Index 530 LogonIncorrect, you connected successfully, but you've just found a different
problem.Reviews
You likely provided an incorrect username or password. Try again, making sure you use
your username
from the Unix server and type your password correctly.
Reader Reviews
Errata
12.2.4
Troubleshooting
Daemons
ByDavid Collier-Brown
, Robert EcksteinServer
, Jay Ts
Once
you'veO'Reilly
confirmed that TCP networking is working properly, the next step is to make sure the
Publisher:
daemons
are
running on the server. This takes three separate tests because no single one of the
Pub Date: February 2003
following will decisively prove that they're working correctly.
ISBN: 0-596-00256-4
To
556
be Pages:
sure they're
Slots: 1
1. Have started
2. Are registered or bound to a TCP/IP port by the operating system
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all3.versions
of Samba
from
2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Are actually
paying
attention
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
12.2.4.1
Tracking
daemon
startup
shared files
and printers
from Unix
clients.
First, check the Samba logs. If you've started the daemons, the message smbdversionnumberstarted
should appear. If it doesn't, you need to restart the Samba daemons.
If the daemon reports that it has indeed started, look out for bindfailedonport139socket_addr=0
(Addressalreadyinuse). This means another daemon has been started on port 139 (smbd ). Also,
nmbd will report a similar failure if it cannot bind to port 137. Either you've started them twice, or the
inetd server has tried to provide a daemon for you. If it's the latter, we'll diagnose that in a moment.
COMMAND
0:03
init [2]
SW
0:00
(kflushd)
0:14
nmbd -D3
237 ?
0:11
smbd -D3
Table ofhave
Contents
ports. The netstat command will tell you if this has been done. Run the command netstat-a on the
Index
server, and look for lines mentioning netbios,137, or 139:
Reviews
Errata
Using
Samba,
2nd Edition
Active
Internet
connections
(including servers)
Local Address
Foreign Address
(state)
*.137
*.*
*.139
*.*
LISTEN
8760
server.139
client.1439
ESTABLISHED
Publisher: O'Reilly
udp
tcp
ISBN: 0-596-00256-4
Pages: 556
tcp
Slots:
83701
Among similar lines, there should be at least one UDP line for *.netbios- or *.137. This indicates that
thenmbd server is registered and (we hope) is waiting to answer requests. There should also be at least
one
TCP
line mentioning
*.netbiosor *.139, and
it willtoprobably
be in the LISTEN
state.
means
Using
Samba,
Second Edition
is a comprehensive
guide
Samba administration.
This
newThis
edition
covers
that
smbd is of
upSamba
and listening
forto
connections.
all versions
from 2.0
2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
There
might
other
lines indicating
connections
from smbd
to clients,
one
each client.
are
Samba's
newbe
role
as aTCP
primary
domain controller
and domain
member
server,
itsfor
support
for theThese
use of
usually
in
the
ESTABLISHED
state.
If
there
are
smbd
lines
in
the
ESTABLISHED
state,
smbd
is
definitely
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
running.
If there
is only one
in clients.
the LISTEN state, we're not sure yet. If both of the lines are missing,
shared files
and printers
fromline
Unix
a daemon has not succeeded in starting, so it's time to check the logs and then go back to Chapter 2.
If there is a line for each client, it might be coming either from a Samba daemon or from the master IP
daemon,inetd. It's quite possible that your inetd startup file contains lines that start Samba daemons
without your realizing it; for instance, the lines might have been placed there if you installed Samba as
part of a Linux distribution. The daemons started by inetd prevent ours from running. This problem
typically produces log messages such as bindfailedonport139socketaddr=0(Addressalreadyin
use).
Check your /etc/inetd.conf ; unless you're intentionally starting the daemons from there, netbios-ns
(UDP port 137) or netbios-ssn (tcp port 139) servers should be mentioned there. If your system is
providing an SMB daemon via inetd, lines such as the following will appear in the inetd.conf file:
netbios-ssn stream tcp nowait root /usr/local/samba/bin/smbd smbd
netbios-ns dgram udp wait root /usr/local/samba/bin/nmbd nmbd
If your system uses xinetd instead of inetd, see Chapter 2 for details concerning its configuration.
Table isn't
of Contents
an easy test for nmbd. If the telnet test and the netstat test both say that an
smbd is running,
there is a good chance that netstat will also be correct about nmbd running.
Index
Reviews
Reader Reviews
12.2.4.5
Testing
Erratadaemons with testparm
Using Samba, 2nd Edition
Once
you
know there's
a daemon,
you
By
David
Collier-Brown
, Robert
Eckstein, Jay
Ts should always run testparm, in hopes of getting something such
as the following:
Publisher: O'Reilly
$testparm
Processing
Slots: 1 section "[homes]"
Processing section "[printers]" ...
Processing
Using Samba,section
Second "[tmp]"
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Loaded
services
OK. ... tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
graphicalfile
configuration
Samba's new role as a primary domain controller and domain member server, its support for the use of
The
testparm
program authentication
normally reports
the
processing
of a series
of host
sections
responds
with Loaded
Windows
NT/2000/XP
and
filesystem
security
on the
Unixand
system,
and accessing
services
file
OK
if
it
succeeds.
If
not,
it
reports
one
or
more
of
the
following
messages,
which
also
shared files and printers from Unix clients.
appear in the logs as noted:
Allow/Deny connection from account (n) to service
Atestparm-only message produced if you have validuser or invaliduser options set in your
smb.conf. You will want to make sure that you are on the valid user list, and that root,bin, etc.,
are on the invalid user list. If you don't, you will not be able to connect, or users who shouldn't will
be able to.
Warning: You have some share names that are longer than eight chars
For anyone using Windows for Workgroups and older clients. They fail to connect to shares with
long names, producing an overflow message that sounds confusingly like a memory overflow.
Warning: [name] service MUST be printable!
A printer share lacks a printable=yes option.
No path in service name using [name]
A file share doesn't know which directory to provide to the user, or a print share doesn't know
which directory to use for spooling. If no path is specified, the service will try to run with a path of
/tmp, which might not be what you want.
Note: Servicename is flagged unavailable
Just a reminder that you have used the available=no option in a share.
Can't find include file [name]
A configuration file referred to by an include option did not exist. If you were including the file
unconditionally, this is an error and probably a serious one: the share will not have the
configuration you intended. If you were including it based on one of the % variables, such as %a
(architecture), you will need to decide whether, for example, a missing Windows for Workgroups
configuration file is a problem. It often isn't.
Can't copy service name, unable to copy to itself
Indicates
thatofaContents
global-only parameter has been used in an individual share. Samba ignores the
Table
parameter.
Index
Reviews
Errata
After the testparm test, repeat it with (exactly) three parameters: the name of your smb.conf file, the
Reader Reviews
name of your client, and its IP address:
Using
Samba, /usr/local/samba/lib/smb.conf
2nd Edition
#testparm
client 192.168.236.10
This will run one more test that checks the hostname and address against hostsallow and hostsdeny
options
and might produce the Allowconnectionfromhostnametoservice and/or Denyconnection
Publisher: O'Reilly
fromhostnametoservice messages for the client system. These messages indicate that you have hosts
Pub Date: February 2003
allow and/or hostsdeny options in your smb.conf, and they prohibit access from the client system.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Thepublic=yes option in the [temp] share is just for testing. You probably don't
want people without accounts storing things on your Samba server, so you should
comment it out when you're done.
Table of Contents
Index
Reviews
Server=[localhost]
Reader Reviews
User=[davecb]
Errata
Using
Samba, 2nd Edition
Workgroup=[EXAMPLE]
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Domain=[EXAMPLE]
Publisher: O'Reilly
Sharename
Type
ISBN: 0-596-00256-4
---------
-----
Comment
----------
Pages: 556
Slots: 1
temp
Disk
IPC$
IPC
directories
Usinghomes
Samba, Second Disk
Edition is a Home
comprehensive
guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
This
machine
does configuration
not have a browse
list for Windows 2000, ME, and XP, the book also explores
the SWAT
graphical
tool. Updated
Samba's new role as a primary domain controller and domain member server, its support for the use of
If
you received
this output,
move on and
to the
next section,
Section
12.2.5.3.
Onsystem,
the other
hand,
if you
Windows
NT/2000/XP
authentication
filesystem
security
on the
host Unix
and
accessing
receive
an
error,
check
the
following:
shared files and printers from Unix clients.
If you get Get_hostbyname:unknownhostlocalhost, either you've spelled its name wrong or there
actually is a problem (which should have been seen back in Section 12.2.2.2). In the latter case,
move on to Section 12.2.7, later in this chapter.
If you get Connecterror:Connectionrefused, the server was found, but it wasn't running an
nmbd daemon. Skip back to Section 12.2.4, earlier in this chapter, and retest the daemons.
If you get the message Yourserversoftwareisbeingunfriendly, the initial session request
packet got a garbage response from the server. The server might have crashed or started
improperly. The common causes of this can be discovered by scanning the logs for the following:
Invalid command-line parameters to smbd ; see the smbd manual page.
A fatal problem with the smb.conf file that prevents the startup of smbd. Always check your
changes with testparm, as was done in Section 12.2.4.5, earlier in this chapter.
Missing directories where Samba is supposed to keep its log and lock files.
The presence of a server already on the port (139 for smbd, 137 for nmbd ), preventing the
daemon from starting.
If you're using inetd (or xinetd ) instead of standalone daemons, be sure to check your
/etc/inetd.conf (or xinetd configuration files) and /etc/services entries against their manual pages
for errors as well.
If you get a Password: prompt, your guest account is not set up properly. The -U% option tells
smbclient to do a "null login," which requires that the guest account be present but does not require
it to have any privileges.
If you get the message SMBtconXfailed.ERRSRV--ERRaccess, you aren't permitted access to the
server. This normally means you have a hostsallow option that doesn't include the server or a
hostsdeny option that does. Recheck with the command testparmsmb.confyour_hostname
your_ip_address (see Section 12.2.4.5), and correct any unintended prohibitions.
Table of
Contents \\server\temp to connect to the server's [temp] share and to see if you
can connect toIndex
a file service. You should get the following response:
Reviews
Reader Reviews
Errata
$smbclient '\\server\temp'
Server time is Tue May
Using Samba, 2nd Edition
By
David
, Robert Eckstein, Jay Ts
smb:
\>Collier-Brown
quit
YouPublisher:
might receive
O'Reilly the following errors:
Pub Date: February 2003
IfISBN:
you 0-596-00256-4
get Get_Hostbyname:Unknownhostname,Connecterror:Connectionrefused, or Your
Pages:
server556
softwareisbeingunfriendly, see the previous section, Section 12.2.5.2, for the
Slots: 1
diagnoses.
If you get the message servertemp:Notenough`\'charactersinservice, you likely didn't quote
the address, so Unix stripped off backslashes. You can also write the command:
\\\\server\\temp
Usingsmbclient
Samba, Second
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
or: graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
Samba's new role as a primary domain controller and domain member server, its support for the use of
smbclient //server/temp
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Now, provide your Unix account password to the Password: prompt. If you then get an smb:\> prompt, it
worked. Enter quit and continue on to the next section, Section 12.2.5.4. If you got SMBtconXfailed.
ERRSRV--ERRinvnetname, the problem can be any of the following:
A wrong share name: you might have spelled it wrong, it might be too long, it might be in mixed
case, or it might not be available. Check that it's what you expect with testparm (see the earlier
section,Section 12.2.4.5).
Asecurity=share parameter in your Samba configuration file, in which case you might have to
add-Uyour_account to the smbclient command.
An erroneous username.
An erroneous password.
Aninvalidusers or validusers option in your smb.conf file that doesn't allow your account to
connect. Recheck using testparmsmb.confyour_hostname your_ip_address (see the earlier
section,Section 12.2.4.5).
Avalidhosts option that doesn't include the server, or an invalidhosts option that does. Also
test this with testparm.
A problem in authentication, such as if shadow passwords or the Password Authentication Module
(PAM) is used on the server, but Samba is not compiled to use it. This is rare, but it occasionally
happens when a SunOS 4 Samba binary (with no shadow passwords) is run without recompilation
on a Solaris system (with shadow passwords).
Theencryptedpasswords=yes option is in the configuration file, but no password for your account
is in the smbpasswd file.
You have a null password entry, either in Unix /etc/passwd or in the smbpasswd file.
You are connecting to [temp], and you do not have the guestok=yes option in the [temp] section
of the smb.conf file.
You are connecting to [temp] before connecting to your home directory, and your guest account
isn't set up correctly. If you can connect to your home directory and then connect to [temp], that's
the problem. See Chapter 2 for more information on creating a basic Samba configuration file.
A bad guest account will also prevent you from printing or browsing until after you've logged in to
your home directory.
Table of Contents
Index reason for this failure that has nothing at all to do with passwords: the path parameter
There is one more
Reviews
in your smb.conf
file might point somewhere that doesn't exist. This will not be diagnosed by testparm,
Reviews
and most SMBReader
clients
can't distinguish it from other types of bad user accounts. You will have to check it
manually.
Errata
Once
you have connected to [temp] successfully, repeat the test, this time logging in to your home
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
directory (e.g., map network drive server\davecb). If you have to change anything to get that to work,
retest[temp] again afterward.
Publisher: O'Reilly
Run the command netuse*\server\temp on the Windows client to see if it can connect to the server.
You should be prompted for a password, then receive the response Thecommandwascompleted
successfully.
Using
Edition
is a steps
comprehensive
to Samba
This new edition covers
If thatSamba,
worked,Second
continue
with the
in the nextguide
section,
Sectionadministration.
12.2.5.5. Otherwise:
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
If you
get
Theas
specified
shared
directory
cannot
befound,
or Cannot
locate
share
Samba's
new
role
a primary
domain
controller
and domain
member
server,
itsspecified
support for
the use of
name,
the
directory
name
is
either
misspelled
or
not
in
the
smb.conf
file.
This
message
can also
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
warn
a name
thatfrom
is inUnix
mixed
case, including spaces, or that is longer than eight characters.
shared
filesofand
printers
clients.
If you get Thecomputernamespecifiedinthenetworkpathcannotbelocated or Cannotlocate
specifiedcomputer, the directory name has been misspelled, the name service has failed, there is
a networking problem, or the hostsdeny option includes your host.
If it is not a spelling mistake, you need to double back at least to Section 12.2.5.3 to
investigate why it doesn't connect.
Ifsmbclient does work, there is a name service problem with the client name service, and you
need to go forward to Section 12.2.6.2 and see if you can look up both the client and server
withnmblookup.
If you get Thepasswordisinvalidfor\server\username, your locally cached copy on the client
doesn't match the one on the server. You will be prompted for a replacement.
Each Windows 95/98/Me client keeps a local password file, but it's really just a
cached copy of the password it sends to Samba and NT/2000/XP servers to
authenticate you. That's what is being prompted for here. You can still log on
to a Windows system without a password (but not to NT/2000/XP).
If you provide your password and it still fails, your password is not being matched on the server,
you have a validusers or invalidusers list denying you permission, NetBEUI is interfering, or
the encrypted password problem described in the next paragraph exists.
If your client is Windows NT 4.0, NT 3.5 with Patch 3, Windows 95 with Patch 3, Windows 98, any of
these with Internet Explorer 4.0, or any subsequent version of Windows, the system will default to
Microsoft encryption for passwords. In general, if you have installed a major Microsoft product on
any of the older Windows versions, you might have applied an update and turned on encrypted
passwords. If the client is defaulting to encrypted passwords, you will need to specify encrypt
passwords=yes in your Samba configuration file if you are using a version of Samba prior to
Samba 3.0.
Reader Reviews
Errata
If you have a mixed-case password on Unix, the client is probably sending it in all one case. If
changing your password to all one case works, this was the problem. Regrettably, all but the oldest
ByDavid
Collier-Brown
, Robert
Eckstein
, Jay Ts
clients
support
uppercase
passwords,
so Samba will try once with the password in uppercase and
once in lowercase. If you wish to use mixed-case passwords, see the passwordlevel option in
Chapter
9 for a workaround.
Publisher:
O'Reilly
Using Samba, 2nd Edition
You might have a validusers problem, as tested with smbclient (see the earlier section, Section
ISBN: 0-596-00256-4
12.2.5.3).
Pages: 556
Slots:
1
You
might
have the NetBEUI protocol bound to the Microsoft client. This often produces long
timeouts and erratic failures and is known to have caused failures to accept passwords in the past.
Unless you absolutely need the NetBEUI protocol, remove it.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba
from
2.0 to
selected
features one
frompiece
an alpha
versionto
ofanother.
3.0, as well as
The term
"bind"
is 2.2,
usedincluding
here to mean
connecting
of software
the SWAT graphical
configuration
tool. Updated
for Windows
and XP,
bookin
also
When
configured correctly,
the Microsoft
SMB2000,
client ME,
is "bound
to"the
TCP/IP
theexplores
Samba's new role
as a primary
controller
and domain
server,
its support
for the use of
bindings
sectiondomain
of the TCP/IP
properties
panelmember
under the
Windows
95/98/Me
Windows NT/2000/XP
authentication
and filesystem
security
on the
host Unix
system,
andcard.
accessing
Network
icon in the Control
Panel. TCP/IP
in turn
is bound
to an
Ethernet
This
shared files andisprinters
Unix
clients.
not thefrom
same
sense
of the word as binding an SMB daemon to a TCP/IP port.
Table of Contents
Networking problem
Index
BadReviews
path parameter in smb.conf
Reader Reviews
Errata
hosts
deny line that excludes you
Publisher: O'Reilly
Pub
2003locatespecifiedsharename,
IfDate:
you February
get Cannot
Once you
can
Slots:
1 reliably connect to the share, try again, this time using your home directory. If you have to
change something to get home directories working, retest with the first share, and vice versa, as we
showed in the earlier section, "Testing connections with net use." As always, if Explorer fails, drop back to
that section and debug the connection there.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
12.2.6
Troubleshooting
Browsing
the SWAT
graphical configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
and this
filesystem
on theit host
system,
and
accessing
Finally,
we
come to browsing.
We've left
for last,security
not because
is theUnix
most
difficult,
but
because it's
shared
files and
from
Unix clients.
both
optional
andprinters
partially
dependent
on a protocol that doesn't guarantee delivery of a packet. Browsing
is hard to diagnose if you don't already know that all the other services are running.
Browsing is purely optional: it's just a way to find the servers on your network and the shares that they
provide. Unix has nothing of the sort and happily does without. Browsing also assumes all your systems
are on a local area network (LAN) where broadcasts are allowable.
First, the browsing mechanism identifies a system using the unreliable UDP protocol; it then makes a
normal (reliable) TCP/IP connection to list the shares the system provides.
Sharename
Type
Comment
---------
----
-------
cdrom
Disk
CD-ROM
cl
Printer
Color Printer 1
davecb
Disk
Home Directories
Server
Comment
Table of Contents
Index
---------
Reviews
-------
Reader Reviews
SERVER
Errata
Samba 2.2.5
Workgroup
Master
Publisher: O'Reilly
--------------Pub
Date: February 2003
ISBN: 0-596-00256-4
EXAMPLE
Pages: 556
SERVER
Slots: 1
If you didn't get a Sharename list, the server is not allowing you to browse any shares. This should
not be the case if you've tested any of the shares with Windows Explorer or the net use command.
If you haven't done the smbclient-Llocalhost-U% test yet (see the earlier section, Section
do it now.
An is
erroneous
guest account
preventadministration.
the shares from
being
Also,
Using12.2.5.2),
Samba, Second
Edition
a comprehensive
guidecan
to Samba
This
newseen.
edition
covers
check the
smb.conf
file
to to
make
you do
not have
the option
=no anywhere
in it:
weas
all versions
of Samba
from
2.0
2.2,sure
including
selected
features
frombrowsable
an alpha version
of 3.0, as
well
suggest
using aconfiguration
minimal smb.conf
file (seefor
theWindows
earlier section,
Section
Youalso
need
to have
the SWAT
graphical
tool. Updated
2000, ME,
and 12.2.5.1).
XP, the book
explores
browsable
enabled
(whichdomain
is the default)
to see
share.
Samba's
new role
as a primary
controller
and the
domain
member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
If files
you didn't
get a browse
list,clients.
the server is not providing information about the systems on the
shared
and printers
from Unix
network. At least one system on the net must support browse lists. Make sure you have local
master=yes in the smb.conf file if you want Samba to be the local master browser.
If you got a browse list but didn't get /tmp, you probably have a smb.conf problem. Go back to
Section 12.2.4.5.
If you didn't get a workgroup list with your workgroup name in it, it is possible that your workgroup
is set incorrectly in the smb.conf file.
If you didn't get a workgroup list at all, ensure that workgroup=EXAMPLE is present in the smb.conf
file.
If you get nothing, try once more with the options -Iip_address-nnetbios_name -Wworkgroup d3 with the NetBIOS and workgroup name in uppercase. (The -d3 option sets the log /debugging
level to 3.) Then check the Samba logs for clues.
If you're still getting nothing, you shouldn't have gotten this far; double back to at least Section 12.2.3.1,
or perhaps Section 12.2.2.4. On the other hand:
If you get SMBtconXfailed.ERRSRV--ERRaccess, you aren't permitted access to the server. This
normally means you have a hostsallow option that doesn't include the server or a hostsdeny
option that does.
If you get Badpassword, you presumably have one of the following:
An incorrect hostsallow or hostsdeny line
An incorrect invalidusers or validusers line
A lowercase password and OS/2 or Windows for Workgroups clients
If you get Connectionrefused, the smbd server is not running or has crashed. Check that it's up,
running, and listening to the network with netstat. See the earlier section, Section 12.2.4.
Table of Contents
Index
If you get
Get_Hostbyname:Unknownhostname, you've made a spelling error, there is a mismatch
between Reviews
the Unix and NetBIOS hostname, or there is a name service problem. Start name service
Reader
Reviews
debugging
as discussed
in the earlier section, Section 12.2.5.4. If this works, suspect a name
Errata
mismatch, and go to the later section, Section 12.2.9.
If you get Sessionrequestfailed, the server refused the connection. This usually indicates an
internal error, such as insufficient memory to fork a process.
Publisher:
If you O'Reilly
get Yourserversoftwareisbeingunfriendly,
Pub
Date: February
2003
garbage
response
Pages: 556
IfSlots:
you 1suspect the server is not running, go back to Section 12.2.4.2 to see why the server daemon
isn't responding.
12.2.6.2
Testing
theEdition
serveriswith
nmblookup guide to Samba administration. This new edition covers
Using Samba,
Second
a comprehensive
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
This
will test
the "advertising"
system
for Windows
name
services
Advertising
works
the SWAT
graphical
configuration
tool.used
Updated
for Windows
2000,
ME, and
and browsing.
XP, the book
also explores
by
broadcasting
one's
or willingness
to provide
services.
It is server,
the partits
of support
browsing
an
Samba's
new role
as a presence
primary domain
controller
and domain
member
forthat
theuses
use of
unreliable
protocol (UDP)
and works only
on broadcast
networks
such
as Unix
Ethernets.
The
nmblookup
Windows NT/2000/XP
authentication
and filesystem
security
on the
host
system,
and
accessing
program
broadcasts
name
queries
the hostname you provide and returns its IP address and the name
shared files
and printers
from
Unix for
clients.
of the system, much as nslookup does with DNS. Here, the -d (debug or log-level) and -B (broadcast
address) options direct queries to specific systems.
First, we check the server from itself. Run nmblookup with a -B option of your server's name (to tell it to
send the query to the Samba server) and a parameter of _ _SAMBA_ _ as the symbolic name to look up.
You should get:
$nmblookup -B server _ _SAMBA_ _
Added interface ip=192.168.236.86 bcast=192.168.236.255 nmask=255.255.255.0
Sending queries to 192.168.236.86 192.168.236.86 _ _SAMBA_ _
You should get the IP address of the server, followed by the name _ _SAMBA_ _ , which means that the
server has successfully advertised that it has a service called _ _SAMBA_ _ , and therefore at least part of
NetBIOS name service works.
If you get Name_queryfailedtofindname_ _SAMBA_ _, you might have specified the server
name to the -B option, or nmbd is not running. The -B option actually takes a broadcast address:
we're using a computer name to get a unicast address and to ask the server if it has claimed _
_SAMBA_ _. Try again with nmblookup-Bip_address, and if that fails too, nmbd isn't claiming the
name. Go back briefly to the earlier section, "Testing daemons with testparm," to see if nmbd is
running. If so, it might not be claiming names; this means that Samba is not providing the browsing
servicea configuration problem. If that is the case, make sure that smb.conf doesn't contain the
optionbrowsing=no.
Next, check the IP address of the client from the server with nmblookup using the -B option for the
client's name and a parameter of '*' meaning "anything," as shown here:
$nmblookup -B client '*'
Sending queries to 192.168.236.10 192.168.236.10 *
Got a positive name query response from 192.168.236.10 (192.168.236.10)
You
might getTable
the following
of Contentserror:
Index
Reviews
If you receive Name-queryfailedtofindname*, you have made a spelling mistake, or the client
Reader Reviews
software on the PC isn't installed, started, or bound to TCP/IP. Double back to Chapter 3 and ensure
Errata
that you have a client installed that is listening to the network.
ByDavid Collier-Brown
, Robert
, Jay Ts options if you had any failures:
Repeat
the command
withEckstein
the following
Publisher: O'Reilly
ISBN: 0-596-00256-4
Pages:
556
If
nmblookup
-B127.0.0.1
Index
Reviews
Reader
Reviews
12.2.6.5
Testing
client
browsing with net view
Errata
Using
Samba,
2nd
Edition
On the
client,
run
the command
If this works, continue with the later section Section 12.3.1. Otherwise:
Pub Date: February 2003
ISBN: 0-596-00256-4
If
you 556
get Networknamenotfound for the name you just tested in the earlier section, Section
Pages:
12.2.6.3,
there is a problem with the client software itself. Double-check this by running nmblookup
Slots: 1
on the client; if it works and net view doesn't, the client is at fault.
Ifnmblookup fails, there is a NetBIOS name service problem, as discussed in the later section,
Section 12.2.9.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
from
2.0the
tonecessary
2.2, including
selected
features
anis
alpha
version of to
3.0, as well as
If you of
getSamba
Youdonot
have
access
rights,
or Thisfrom
server
notconfigured
the SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
listsharedresources, either your guest account is misconfigured (see the earlier section,
Section
Samba's
new
role
as
a
primary
domain
controller
and
domain
member
server,
its
support
for
the
12.2.5.2) or you have a hostsallow or hostsdeny line that prohibits connections from your use of
Windows
NT/2000/XP
authentication
security
host Unix
system,
and
system.
These problems
should and
havefilesystem
been detected
by on
thethe
smbclient
tests
starting
in accessing
the earlier
shared
files
and
printers
from
Unix
clients.
section,Section 12.2.6.1.
If you get Thespecifiedcomputerisnotreceivingrequests, you have misspelled the name,
the system is unreachable by broadcast (tested in the earlier section, Section 12.2.6.4), or it's not
runningnmbd.
If you get Badpassworderror, you're probably encountering the Microsoft-encrypted password
problem, as discussed earlier in this chapter and in Chapter 9, with its corrections.
Table of Contents
or it is a problem related to a topic we have already covered, and further analysis is required. Name
Index
resolution is often related to difficulties with Samba, so we cover it in more detail in the next sections. If
Reviews
you know your problem is not related to name resolution, skip to the Section 12.3 at the end of the
Reader Reviews
chapter.
Errata
This section looks at simple troubleshooting of all the name services you'll encounter, but only for the
Pub Date: February 2003
common
problems that affect Samba.
ISBN: 0-596-00256-4
TherePages:
are several
556
good references for troubleshooting particular name services: Paul Albitz and Cricket
Liu'sDNS
and
Bind
(O'Reilly) covers the DNS, Hal Stern'sNFS and NIS (O'Reilly) covers NIS ("Yellow
Slots: 1
pages"), while Windows Internet Name Service (WINS), hosts/LMHOS TS files, and NIS+ are best covered
by their respective vendors' manuals.
The problems addressed in this section are as follows:
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
Namegraphical
services configuration
are identified.tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
A hostname
can'tauthentication
be looked up. and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
The long (FQDN) form of a hostname works but the short form doesn't.
The short form of the name works, but the long form doesn't.
A long delay occurs before the expected result.
On the clients, the name services are all set in the TCP/IP Properties panel of the Networking Control
Panel, as discussed in Chapter 3. You might need to check there to see what you've actually turned on.
On the server, see if a /etc/resolv.conf file exists. If it does, you're using DNS. You might be using the
others as well, though. You'll need to check for NIS and combinations of services.
Check for a /etc/nsswitch.conf file on Solaris and other System V Unix operating systems. If you have
one, look for a line that begins with host: followed by one or more of files,bind,nis, or nis+. These
are the name services to use, in order, with optional extra material in square brackets. The files
keyword is for using HOSTS files, while bind (the Berkeley Internet Name Daemon) refers to using DNS.
Table of Contents
Index
If the client and server differ, the first thing to do is to get them in sync. Clients can use DNS, WINS,
Reviews
HOSTS, and LMHOSTS
files, but not NIS or NIS+. Servers can use HOSTS and LMHOSTS files, DNS, NIS
Reviews
or NIS+, and Reader
winbind,
but not WINSeven if your Samba server provides WINS services. If you can't get
Errata
all the systems
to use the same services, you'll have to check the server and the client carefully for the
Using
Samba,
2nd
Edition
same data.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
You can also make use of the -R (resolve order) option for smbclient. If you want to troubleshoot WINS,
for example, you'd say:
Publisher: O'Reilly
The possible
settings are hosts (which means whatever the Unix system is using, not just /etc/hosts
Pages: 556
files),lmhosts,
Slots: 1 wins, and bcast (broadcast).
In the following sections, we use the term long name for a fully qualified domain name (FQDN), such as
server.example.com , and the term short name for the host part of an FQDN, such as server.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
12.2.7.2
look
up hostnames
the SWATCannot
graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
Try
the following:
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
DNS
Run nslookupname. If this fails, look for a resolv.conf error, a downed DNS server, or a short/long
name problem (see the next section). Try the following:
Your /etc/resolv.conf file should contain one or more nameserver lines, each with an IP
address. These are the addresses of your DNS servers.
Ping each server address you find. If this fails for one, suspect the system. If it fails for each,
suspect your network.
Retry the lookup using the full domain name (e.g., server.example.com) if you tried the short
name first, or the short name if you tried the long name first. If results differ, skip to the next
section.
Broadcast/ WINS
Broadcast/ WINS does only short names such as server, and not long ones, such as
server.example.com. Run nmblookup-Sserver. This reports everything broadcast has registered
for the name. In our example, it looks like this:
$nmblookup -S server
Looking up status of 192.168.236.86
received 10 names
SERVER
<00> -
M <ACTIVE>
SERVER
<03> -
M <ACTIVE>
SERVER
<1f> -
M <ACTIVE>
SERVER
<20> -
M <ACTIVE>
..__MSBROWSE__.
MYGROUP
MYGROUP
<1b> -
M <ACTIVE>
MYGROUP
Table of Contents <1c> - <GROUP> M <ACTIVE>
Index
MYGROUP
<1d> -
Reviews
Reader Reviews
MYGROUP
Errata
M <ACTIVE>
The required entry is SERVER<00>, which identifies server as being this system's NetBIOS name. You
By
David also
Collier-Brown
, Robert
Eckstein,mentioned
Jay Ts
should
see your
workgroup
one or more times. If these lines are missing,
Broadcast/WINS cannot look up names and will need attention.
Publisher: O'Reilly
Pub Date: February 2003
The numbers
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
NIS
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Tryypmatchnamehosts. If this fails, NIS is down. Find out the NIS server's name by running
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
ypwhich,
andasping
the system
to see
if it's accessible.
Samba's
new role
a primary
domain
controller
and domain member server, its support for the use of
NIS
+
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
If you're running NIS+, try nismatchnamehosts. If this fails, NIS is down. Find out the NIS+
server's name by running niswhich, and ping that system to see if it's accessible.
hosts and HOSTS files
Inspect the HOSTS file on the client (C:\Windows\ Hosts on Windows 95/98/Me, and C:\WINNT
\system32\drivers\etc\hosts on Windows NT/2000/XP). Each line should have an IP number and
one or more names, the primary name first, then any optional aliases. An example follows:
127.0.0.1
localhost
192.168.236.1
dns.svc.example.com
192.168.236.10
client.example.com client
192.168.236.11
backup.example.com loghost
192.168.236.86
server.example.com server
192.168.236.254
router.svc.example.com
On Unix, localhost should always be 127.0.0.1, although it might be just an alias for a hostname on the
PC. On the client, check that there are no #XXX directives at the ends of the lines; these are LAN
Manager/NetBIOS directives and should appear only in LMHOSTS files.
LMHOSTS files
This file is a local source for LAN Manager (NetBIOS) names. It has a format similar to hosts files,
but it does not support long-form domain names (e.g., server.example.com) and can have a
number of optional #XXX directives following the NetBIOS names. There is usually an lmhosts.sam
(for sample) file located in C:\Windows on Windows 95/98/Me, and in
C:\WINNT\system32\drivers\etc on Windows NT/2000/XP, but it's not used unless it is renamed to
Lmhosts in the same directory.
Index
line
with
one
or
more domains in it. One or the other might need to be present to make short
Reviews
names usable; which one depends on the vendor and version of the DNS resolver. Try adding
Reader Reviews
domainyour_domain to resolv.conf, and ask your network or DNS administrator what should be in
Errata
the file.
Using Samba, 2nd Edition
Broadcast/WINS
Broadcast/WINS doesn't support long names; it won't suffer from this problem.
NISPublisher: O'Reilly
Pub Date: February 2003
Try the command ypmatchhostname hosts. If you don't get a match, your tables don't include
ISBN: 0-596-00256-4
short names. Speak to your network manager; short names might be missing by accident or might
Pages: 556
be unsupported as a matter of policy. Some sites don't ever use (ambiguous) short names.
NIS +
Slots: 1
DNS
Test the same name with the nslookup command on the system that is slow (client or server). If
nslookup is also slow, you have a DNS problem. If it's slower on a client, you might have too many
protocols bound to the Ethernet card. Eliminate NetBEUI, which is infamously slow, and, optionally,
Novellassuming you don't need them. This is especially important on Windows 95, which is
particularly sensitive to excess protocols.
Broadcast/ WINS
Test theTable
client
of using
Contents
nmblookup; if it's faster, you probably have the protocols problem as
mentioned
in the previous item.
Index
NIS
Reviews
Reader Reviews
Tryypmatch;
if it's slow, report the problem to your network manager.
Errata
NIS
+
Using Samba, 2nd Edition
ByDavidTry
Collier-Brown
Eckstein, Jay Ts
nismatch,,Robert
similarly.
Thehosts files, if of reasonable size, are always fast. You probably have the protocols problem
mentioned previously under DNS.
ISBN: 0-596-00256-4
lmhosts and LMHOSTS
Pub Date: February 2003
Pages: 556
Slots:is
1 not a name lookup problem; LMHOSTS files are as fast as hosts and HOSTS files.
This
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
When a localhost isn't 127.0.0.1, try the following:
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role as a primary domain controller and domain member server, its support for the use of
DNS
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
sharedThere
files and
printersno
from
Unixfor
clients.
is probably
record
localhost.A127.0.0.1. Arrange to add one, as well as a reverse
entry,1.0.0.127.IN-ADDR.ARPAPTR127.0.0.1.
Broadcast/WINS
Not applicable.
NIS
Iflocalhost isn't in the table, add it.
NIS +
Iflocalhost isn't in the table, add it.
hosts and HOSTS
Add a line that says 127.0.0.1localhost.
LMHOSTS
Not applicable.
12.2.8.1 Netmasks
Using the netmask, it is possible to determine which addresses can be reached directly (i.e., which are on
the local network) and which addresses require forwarding packets through a router. If the netmask is
wrong, the systems will make one of two mistakes. One is to route local packets via a router, which is an
expensive waste of timeit might work reasonably fast, it might run slowly, or it might fail utterly. The
second mistake is to fail to send packets from a remote system to the router, which will prevent them
from being forwarded to the remote system.
The netmask is a number like an IP address, with one-bits for the network part of an address and zerobits for the host portion. It is used as a bitmask to mask off parts of the address inside the TCP/IP code.
If the mask is 255.255.0.0, the first 2 bytes are the network part and the last 2 are the host part. More
common is 255.255.255.0, in which the first 3 bytes are the network part and the last one is the host
part.
For example, let's
Table say
of Contents
your IP address is 192.168.0.10 and the Samba server is 192.168.236.86. If your
netmask happens
Indexto be 255.255.255.0, the network part of the address is the first 3 bytes, and the host
part is the lastReviews
byte. In this case, the network parts are different, and the systems are on different
networks:
Reader Reviews
Errata
Network part
Host part
192
168 000
Publisher:
O'Reilly
Pub
Date:
February
192
168
235
10
2003
86
ISBN: 0-596-00256-4
Pages:
556 happens to be 255.255.0.0, the network part is just the first 2 bytes. In this case, the
If your
netmask
Slots:
1 match, and so the two systems are on the same network:
network
parts
Network
part
Host part
Using Samba, Second
Edition is
a comprehensive guide to Samba administration.
This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
192 168
000 10
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
192 168 new role as a primary domain controller and domain
236 86member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Make sure the netmask in use on each system matches the structure of your network. On every subnet,
the netmask should be identical on each system.
Network part
Host part
IP address
86
Netmask
000
Broadcast
255
In this example, the broadcast address on the 192.168.236 network is 192.168.236.255. There is also an
old "universal" broadcast address, 255.255.255.255. Routers are prohibited from forwarding these, but
most systems on your local network will respond to broadcasts to this address.
through 172.31.*.*, and 254 class C networks, 192.168.1.* through 192.168.254.*. The domain
example.com is also reserved for unconnected networks, explanatory examples, and books.
If you're actually connecting to the Internet, you'll need to get an appropriate IP address and a domain
name, probably through the same company that provides your connection.
Table of Contents
Reader Reviews
If you haven't recorded your IP address, you can learn it through the ifconfig command on Unix or the
Index
ipconfig command on Windows. (Check your manual pages for any options required by your brand of
Reviews
Unix. For example, ifconfig-a works on Solaris.) You should see output similar to the following:
$ifconfig -aErrata
Using Samba, 2nd Edition
le0:
flags=63<UP,BROADCAST,NOTRAILERS,RUNNING
>
ByDavid
Collier-Brown, Robert Eckstein, Jay Ts
inet 192.168.236.11 netmask ffffff00 broadcast 192.168.236.255
Publisher: O'Reilly
lo0: flags=49<<>UP,LOOPBACK,RUNNING<>>
ISBN: 0-596-00256-4
Pages:
inet556
127.0.0.1
netmask ff000000
Slots: 1
One of the interfaces will be loopback (in our examples, lo0), and the other will be the regular IP
interface. The flags should show that the interface is running, and Ethernet interfaces will also say they
support broadcasts (PPP interfaces don't). The other places to look for IP addresses are /etc/hosts files,
Windows
HOSTS
files, Windows
files, NIS,
NIS+,
and DNS.
Using Samba,
Second
Edition isLMHOSTS
a comprehensive
guide
to Samba
administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's Troubleshooting
new role as a primary domain
controller
and domain member server, its support for the use of
12.2.9
NetBIOS
Names
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Historically, SMB protocols have depended on the NetBIOS name system, also called the LAN Manager
name system. This was a simple scheme where each system had a unique 20-character name and
broadcast it on the LAN for everyone to know. With TCP/IP, we tend to use names such as
client.example.com, stored in /etc/hosts files through DNS or WINS.
The usual mapping of domain names such as server.example.com to NetBIOS names simply uses the
server part as the NetBIOS name and converts it to uppercase. Alas, this doesn't always work, especially
if you have a system with a 21-character name; not everyone uses the same NetBIOS and DNS names.
For example, corpvm1 along with vm1.corp.com is not unusual.
A system with a different NetBIOS name and domain name is confusing when you're troubleshooting; we
recommend that you try to avoid this wherever possible. NetBIOS names are discoverable with smbclient
:
If you can list shares on your Samba server with smbclient-Lshort_name, the short name is the
NetBIOS name.
If you get Get_Hostbyname:Unknownhostname, there is probably a mismatch. Check in the
smb.conf file to see if the NetBIOS name is explicitly set.
Try to list shares again, specifying -I and the IP address of the Samba server (e.g., smbclient-L
server-I192.168.236.86). This overrides the name lookup and forces the packets to go to the IP
address. If this works, there was a mismatch.
Try with -I and the full domain name of the server (e.g., smbclient-Lserver-I
server.example.com). This tests the lookup of the domain name, using whatever scheme the
Samba server uses (e.g., DNS). If it fails, you have a name service problem. You should reread the
earlier section, Section 12.2.7, after you finish troubleshooting the NetBIOS names.
Try with the -n (NetBIOS name) option, giving it the name you expect to work (e.g., smbclient-n
server-Lserver-12), but without overriding the IP address through -I. If this works, the name
you specified with -n is the actual NetBIOS name of the server. If you receive Get-Hostbyname:
UnknownhostSERVER, it's not the right server yet.
If nothing is working so far, repeat the tests specifying -Uusername and -Wworkgroup, with the
username and workgroup in uppercase, to make sure you're not being derailed by a user or
workgroup mismatch.
If still nothing works and you had evidence of a name service problem, troubleshoot the name
service (see the earlier section, Section 12.2.7) and then return to the NetBIOS name service.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
12.3.1 Documentation
and FAQs
Reviews
Reader Reviews
It's OK to read the documentation. Really. Nobody can see you, and we won't tell. In fact, Samba ships
Errata
with a large set
of documentation files, and it is well worth the effort to at least browse through them,
Using Samba, 2nd Edition
either in the distribution directory on your computer under /docs or online at the Samba web site:
By
David Collier-Brown, RobertThe
Eckstein
, Jay
Ts
http://www.samba.org.
most
current
FAQ list, bug information, and distribution locations are located
at the web site, with links to all the Samba manual pages and HOWTOs.
Publisher: O'Reilly
Pub Date: February 2003
12.3.2
ISBN:
Samba
0-596-00256-4
Newsgroups
Pages: 556
UsenetSlots:
newsgroups
1
have always been a great place to get advice on just about any topic. In the past few
years, though, this vast pool of knowledge has developed something that has made it into an invaluable
resource: a memory. Archival and search sites such as the one at Google
(http://groups.google.com/advanced_group_search) have made sifting through years of valuable
solutions
as simple
as Edition
a few mouse
clicks.
Using Samba,
Second
is a comprehensive
guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
The
primary
newsgroup
for Sambatool.
is comp.protocols.smb.
should
your
first
stop
when
the SWAT
graphical
configuration
Updated for WindowsThis
2000,
ME, always
and XP,be
the
book
also
explores
there's
a
problem.
More
often
than
not,
spending
5
minutes
researching
an
error
here
will
save
hours
of
Samba's new role as a primary domain controller and domain member server, its support for the use of
frustration
while
trying
to
debug
something
yourself.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
When searching a newsgroup, try to be as specific as possible, but not too wordy. Searching on actual
error messages is best. If you don't find an answer immediately in the newsgroup, resist the temptation
to post a request for help until you've done a bit more work on the problem. You might find that the
answer is in a FAQ or one of the many documentation files that ship with Samba, or a solution might
become evident when you run one of Samba's diagnostic tools. If nothing works, post a request in
comp.protocols.smb, and be as specific as possible about what you have tried and what you are seeing.
Include any error messages that appear. It might be days before you receive help, so be patient and
keep trying things while you wait.
Once you post a request for help, keep poking at the problem yourself. Most of us
have had the experience of posting a Usenet article containing hundreds of lines of
intricate detail, only to solve the problem an hour later after the article has blazed
its way across several continents. The rule of thumb goes something like this: the
more folks who have read your request, the simpler the solution. Usually this
means that once everyone in the Unix community has seen your article, the
solution will be something simple such as, "Plug the power cord into the wall
socket."
[email protected]
By subscribing to this list, you can automatically receive a message every time one of the Samba
developers updates the Samba source code in the CVS repository. You might want to do this if you
are waiting for a specific bug fix or feature to be applied. To avoid congesting your email inbox, we
suggest using the digest feature, which consolidates messages into a smaller number of emails.
samba-docs@ samba.org
This list is for discussing Samba documentation.
[email protected]
Table of Contents
Index
This mailing
list is for people who are running Samba on the VMS operating system.
Reviews
[email protected]
Reader Reviews
Errata
This is a list for developers to use when discussing precompiled Samba distributions.
[email protected]
Using Samba, 2nd Edition
Searchable versions of the Samba mailing list archives can be found at http://marc.theaimsgroup.com.
Pub Date: February 2003
0-596-00256-4
When ISBN:
posting
messages to the Samba mailing lists, keep in mind that you are sending your message to a
Pages:
556
large audience. The notes in the previous section regarding Usenet postings also apply here. A wellSlots: 1
formulated
question or comment is more likely to be answered, and a poorly conceived message is very
likely to be ignored!
Using
Samba,
Second
Edition is a comprehensive guide to Samba administration. This new edition covers
12.3.4
Further
Reading
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new
role TCP/IP
as a primary
domain
controller and
domain
member
server,
itsO'Reilly
support&for
the use of
1. Hunt,
Craig.
Network
Administration,
Third
Edition.
Sebastopol,
CA:
Associates,
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
1997.
shared files and printers from Unix clients.
2. Hunt, Craig, and Robert Bruce Thompson. Windows NT TCP/IP Network Administration. Sebastopol,
CA: O'Reilly & Associates, 1998.
3. Albitz, Paul, and Cricket Liu. DNS and Bind, Fourth Edition. Sebastopol, CA: O'Reilly & Associates,
1998.
4. Stern, Hal. Managing NFS and NIS, Second Edition. Sebastopol, CA: O'Reilly & Associates, 1991.
Table of Contents
modes we've discussed. Using one of these examples, you can run Samba as a workgroup authentication
Index
server, workgroup
server, primary domain controller, or domain member server.
Reviews
Reviews simple so that they have the most universal application. They can be used as
We have kept Reader
the examples
Errata
starting templates, which you can easily modify to fit your own needs, to get a Samba server up and
Using
Samba,
Editiondelay. The comments inside the files indicate what needs to be changed, and how,
running
with2nd
minimal
to
work
on
a
particular
system
on
your
ByDavid Collier-Brown, Robert
Eckstein
, Jay
Ts network.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
A.1.1 Authentication
and WINS Server
Reader Reviews
Errata
In a workgroup
environment, Samba can be set up with share-level security and without offering WINS
Using Samba, 2nd Edition
name service. This works and is simple, but we generally recommend that user-level security be enabled
By
, Robert Eckstein
, Jay Ts
toDavid
allowCollier-Brown
Windows 95/98/Me
systems
to make use of it. Also, it only takes a single parameter to enable
Samba as a WINS server, resulting in far better network efficiency. Here is the configuration file that
does
it:
Publisher:
O'Reilly
Pub Date: February 2003
[global]
ISBN: 0-596-00256-4
556
#Pages:
replace
Slots: 1
security = user
encrypt passwords = yes
Table of Contents
[homes]
Index
Reviews
comment Reader
= %u'sReviews
Home Directory
Errata
Usingbrowsable
Samba, 2nd Edition
= no
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
read only = no
Publisher: O'Reilly
ISBN: 0-596-00256-4
Pages: 556
# ThisSlots:
is 1a shared directory, accessible by all
# users. Use your own share name and path.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
[d]
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
path NT/2000/XP
= /d
Windows
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
create mask = 0700
read only = no
Generally, you will use a configuration file similar to this one when adding your first Samba server to the
workgroup.
workgroup = METRAN
security = user
encrypt passwords = yes
Table of Contents
# of your
WINS server. If there is none,
Index
Reviews
Reader Reviews
Errata
# ISBN:
The 0-596-00256-4
OS level is set to 17 to allow
Pages: 556
[homes]
comment = %u's Home Directory
browsable = no
read only = no
[d]
path = /d
create mask = 0700
read only = no
Once you have a server in your workgroup handling authentication and WINS, this is the configuration file
to use when adding additional Samba servers to the workgroup.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Reviews
Reader Reviews
Setting up Samba as a primary domain controller is more complicated than the other configurations.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
# Replace
"METRAN"
of your
Windows
NT domain.
all versions
of Samba
from with
2.0 tothe
2.2,name
including
selected
features
from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
workgroup
METRANfrom Unix clients.
shared
files and =
printers
Do not allow
security = user
encrypt passwords = yes
domain logons = yes
Table of Contents
Index
# The location
of user profiles for Windows NT/2000/XP.
Reviews
Reader Reviews
Errata
Usinglogon
Samba,path
2nd Edition
= \\%L\profiles\%u\%m
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
logon
drive = G:
Table of Contents
add userIndex
script = /usr/sbin/useradd -d /dev/null -g 100 -s /bin/false -M %u
Reviews
Reader Reviews
Errata
Provide
Microsoft
Using#Samba,
2nd Edition
Dfs support.
Publisher: O'Reilly
# The Slots:
netlogon
share is required for
1
# functioning as the primary domain controller.
#
MakeSamba,
sure the
directory
used
for the pathguide
exists.
Using
Second
Edition is
a comprehensive
to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
[netlogon]
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
path = /usr/local/samba/lib/netlogon
writable = no
browsable = no
[profiles]
path = /home/samba-ntprof
writable = yes
create mask = 0600
directory mask = 0700
browsable = no
[homes]
comment = Home Directory
browsable = no
read only = no
Table =
of yes
Contents
map archive
Index
Reviews
Reader Reviews
#
The Dfs share.
Errata
Using Samba, 2nd Edition
[dfs]Pages: 556
Slots: 1
[d]
comment = %u's Home Directory
path = /d
create mask = 0700
read only = no
SeeChapter 4 for more information on configuring Samba as a primary domain controller, and see
Chapter 8 for more information about setting up a Microsoft Dfs share.
workgroup = METRAN
Table of Contents
Index
Reviews
# Replace
Reader
"172.16.1.1"
Reviews
with the
Errata
IP address
of
Using#Samba,
2nd Edition
Publisher: O'Reilly
osSlots:
level
= 33
1
= domain
Usingsecurity
Samba, Second
Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
encrypt
passwords
= yes tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT
graphical
configuration
Samba's new role as a primary domain controller and domain member server, its support for the use of
password
serverauthentication
= *
Windows
NT/2000/XP
and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
# Home directories.
[homes]
comment = %u's Home Directory
browsable = no
read only = no
map archive = yes
[printers]
printable = yes
printing = BSD
print command = /usr/bin/lpr -P%p %s
path = /var/tmp
min print space = 2000
Index
Reviews
Reader Reviews
[d]
Errata
path = /d
SeeChapter
10 for more information on sharing printers with Samba.
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
Contents
usually
named
smb.conf.
Most configuration files contain a global section of options that apply to all
Index
services
(shares)
and
a
separate
section for various individual shares. If an option applies only to the
Reviews
global section, [global] appears to the right of its name in the following reference section.
Reader Reviews
Errata
Except where noted, when specifying elements of a list, the elements can be separated by spaces, tabs,
Using Samba, 2nd Edition
commas, semicolons, escaped newlines, or escaped carriage returns.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Following this reference section is a glossary of value types, and a list of variables Samba recognizes.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies a command that stops the shutdown procedure started by shutdown script. The command will
Reviews
be run with the UID of the connected user. New in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Specifies a command that creates a new printer on the system hosting the Samba server. This command
Reviews
runs as root when the Windows NT/2000/XP Add Printer Wizard is run. The command will be passed a
Reader Reviews
printer name, share name, port name, driver name, Windows NT/2000/XP driver location, and Windows
Errata
95/98/Me driver
location, in that order. It will need to add the printer to the system and a share definition
Using
Samba,
2nd
for the printer toEdition
smb.conf. See also add printer wizard,printing, and show add printer wizard.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a command that adds a computer to the Samba server's domain. New in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Specifies a command that creates a new share on the Samba server. This command runs as root when a
Reviews
share is created using the Windows NT/2000/XP Server Manager. The client user must be logged on as
Reviews
theroot user. Reader
The command
will be passed the name of the Samba configuration file, the name of the
Errata
share to be created, the full pathname of a directory on the Samba server (which must already exist),
Using Samba, 2nd Edition
and a string to use as a comment for the share, in that order. The command must add a share definition
forDavid
By
the share
Collier-Brown
to smb.conf.
, Robert Eckstein
See also
, Jayadd
Ts printer command, for adding a print share.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Specifies a command that creates a new user on the system hosting the Samba server. This command
Reviews
runs as root when access to a Samba share is attempted by a Windows user who does not have an
Reader Reviews
account on the hosting system, but does have an account maintained by a primary domain controller on
Errata
a different system.
The command should accept the name of the user as a single argument that matches
Using
Samba,
2nd
Edition adduser commands. Samba honors the %u value (username) as the argument to
the behavior of typical
the
By
David
command.
Collier-Brown
Requires
, Robertsecurity
Eckstein, Jay
=server
Ts
or security=domain. See also delete userscript.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies users who will be granted root permissions on the share by Samba.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies the Active Directory server, used by Samba 3.0 for authenticating clients. Requires security=
Reviews
ads. New in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Specifies the base value that Samba uses when calculating Windows domain security identifier
Reviews
equivalents to Unix UIDs. See also non unix account range. New in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies systems that can connect to the share or shares. If NULL, any system can access the share
Reviews
unless there is a hosts deny option. Synonym for hostsallow.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Allows access to users who lack accounts on the Samba server but have accounts in another, trusted
Reviews
domain. Requires security= server or security=domain.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
announce as = value
[global]
Index
Reader Reviews
Errata
Has Samba announce itself as something other than an NT server. Discouraged because it interferes with
Reviews
serving browse lists.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies what methods Samba tries in turn to authenticate users. New in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a list of shares that always appear in browse lists. Also called preload.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
available = boolean
Index
Reader Reviews
Errata
If set to NO, denies access to a share. The share appears in the browse list, but attempts to access it will
Reviews
fail.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
If set to YES, shares and browsing are provided only on interfaces in an interfaces list (see interfaces).
Reviews
If you set this option to YES, be sure to add 127.0.0.1 to the interfaces list to allow smbpasswd to
Reader Reviews
connect to the local system to change passwords. This is a convenience option; it does not improve
Errata
security.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Sets the size of disk blocks as reported by smbd to the client. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If YES, honors byte range lock requests with time limits. Samba will queue the requests and retry them
Reviews
until the time period expires.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
browsable = boolean
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If YES, serves the browse list to other systems on the network. Avoid changing.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
browseable = boolean
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If YES, uses the exact case the client supplied when trying to resolve a filename. If NO, matches either
Reviews
upper- or lowercase name. Avoid changing. Also called casesignames.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
casesignames = boolean
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Sets the number of seconds between checks when a client asks for notification of changes in a directory.
Reviews
Avoid lowering.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Specifies a command that modifies a share definition on the Samba server. This command runs as root
Reviews
when a share is created using the Windows NT/2000/XP Server Manager. The client user must be logged
on as the rootReader
user.Reviews
The command is passed the name of the Samba configuration file, the name of the
Errata
share to be modified, the full pathname of a directory on the Samba server (which must already exist),
Using Samba, 2nd Edition
and a string to use as a comment for the share, in that order. The command modifies the share definition
forDavid
By
the share
Collier-Brown
in smb.conf.
, Robert Eckstein
See also
, Jayadd
Ts share command and delete share command.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
If set, translates from DOS code pages to the Western European (ISO8859-1), Eastern European
Reviews
(ISO8859-2), Russian Cyrillic (ISO8859-5), or Alternate Russian (KOI8-R) character set. The clientcode
Reader Reviews
page option must
be set to 850. Obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
Index
Errata
Sets the DOS code page explicitly, overriding any previous validchars settings. Examples of values are
Reviews
850 for Western European, 437 for the U.S. standard, and 932 for Japanese Shift-JIS. Obsolete starting
Reader Reviews
with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies the directory that stores code pages. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Allowable values: euc, cap, hex, hexN, sjis, j8bb, j8bj, jis8, j8bh, j8@b, j8@j,j8@h, j7bb, j7bj, jis7,
j7bh, j7@b, j7@j, j7@h, jubb, jubj, junet, jubh, ju@b, ju@j, ju@h
Table of Contents
Reviews
Default:
NULL
Index
Sets the coding system used, notably for Kanji. This is employed for filenames and should correspond to
Reviews
the code pageReader
in use.
The clientcodepage option must be set to 932 ( Japanese Shift-JIS). Obsolete
Errata
starting with Samba 3.0.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
comment = string
Table of Contents
Index
Reader Reviews
Errata
Sets the comment corresponding to a share. The comment appears in places such as a net view listing or
Reviews
through the Network Neighborhood. See also the serverstring configuration option.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Selects a new Samba configuration file to read instead of the current one. Used to relocate the
Reviews
configuration file or used with % variables to select custom configuration files for some users or systems.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
Copies the configuration of an already defined share into the share in which this option appears. Used
Reviews
with% variables to select custom configurations for systems, architectures, and users. Each option
Reader Reviews
specified or copied takes precedence over earlier specifications of the option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Errata
Sets the maximum allowable permissions for new files (e.g., 0755). See also directorymask. To require
Reviews
certain permissions to be set, see forcecreatemask and forcedirectorymask. Also called create
Reader Reviews
mode.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the client-side caching policy, telling them how to cache files offline if they are capable of doing so.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
deadtime = number
[global]
Table of Contents
Index
Errata
Specifies the time in minutes before an unused connection will be terminated. Zero means never. Used to
Reviews
keep clients from tying up server resources for long periods of time. If used, clients must autoreconnect
Reader Reviews
after the specified
period of inactivity. See also keepalive.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Changes the timestamps in log entries from seconds to microseconds. Useful for measuring performance.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Adds the process ID of the Samba server to log lines, making it easier to debug a particular server.
Reviews
Requires debug timestamp = yes to work.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Timestamps all log messages. Can be turned off when it's not useful (e.g., in debugging ). Also called
Reviews
timestamplogs.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Adds the real and effective user ID and group ID of the user being served to the logs, making it easier to
Reviews
debug one particular user.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
debuglevel = number
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the logging level used. Values of 3 or more slow Samba noticeably. Also called loglevel.
Reviews
Recommended value is 1.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
permission to use or that doesn't exist.
Reader Reviews
underscore ( _ ) characters changed to
Samba server.Errata
Use is discouraged. See
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the case in which to store new filenames. LOWER indicates lowercase, and UPPER indicates
Reviews
uppercase.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Used with printer shares being accessed by Windows NT/2000/XP clients to set a default device mode for
Reviews
theprinter. Can be problematic. Use with care.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies a command that removes a printer from the system hosting the Samba server and deletes its
Reviews
service definition from smb.conf. The command is passed a printer name as its only argument. See also
Reviews
add printer Reader
command,
printing, and show add printer wizard.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set to YES, allows delete requests to remove read-only files. This is not allowed in MS-DOS/Windows,
Reviews
but it is normal in Unix, which has separate directory permissions. Used with programs such as RCS.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Specifies a command that deletes a share from the Samba server. The command runs when a user
Reviews
logged in as the root user on a Windows NT/2000/XP system deletes a share using Server Manager. The
Reader Reviews
command is passed the name of the Samba configuration file and the name of the share to be deleted.
The commandErrata
must remove the definition of the share from the configuration file. See also add share
Using
Samba,
Edition
command
and2nd
change
share command.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Sets the command to run as root when a user connects who no longer has an account on the domain's
Reviews
PDC. Honors %u. Can be used to delete the user account automatically from the Samba server's host.
Reader Reviews
Requiressecurity
=domain or security = user. Use with caution. See also add user script.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set to YES, allows delete requests for a directory containing files or subdirectories the user can't see
Reviews
due to the vetofiles option. If set to NO, the directory is not deleted and still contains invisible files.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a list of systems from which to refuse connections. Also called hostsdeny.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies a command to run on the server to return free disk space. Not needed unless the Samba host
Reviews
system'sdfree command does not work properly.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
directory = directory
Table of Contents
Index
Sets the path to the directory provided by a file share or used by a printer share. If the option is omitted
Reviews
in the [homes] share, it is set automatically to the user's home directory; otherwise, it defaults to /tmp.
Reader Reviews
For a printer share,
the directory is used to spool printer files. Honors the %u (user) and %m (machine)
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Errata
Sets the maximum allowable permissions for newly created directories. To require that certain
Reviews
permissions be set, see the forcecreatemask and forcedirectorymask options. Also called
Reader Reviews
directorymode.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents mode
Index
Controls which permission bits can be changed if a user edits the Unix permissions of directories on the
Reviews
Samba server from a Windows system. Any bit that is set in the mask can be changed by the user; any
Reader Reviews
bit that is clear
remains the same on the directory even if the user tries to change it. Requires ntacl
support=YES. Errata
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set to YES, Windows NT/2000/XP systems will downgrade to Lanman-style printing. Prevents printer
Reviews
driver uploading and downloading from working. Use with care. See also use client driver.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If set to YES and if winsserver=YES, looks up hostnames in DNS when they are not found using WINS.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies users who are in the Domain Admins group and have domain administrator authority when
Reviews
Samba is the PDC. See also domain guest group and domain logons. Useful in Samba 2.2 only.
Reader Reviews
Obsolete in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies users who are in the Domain Guest group when Samba is the PDC. See also domain admin
Reviews
group and domain logons. Useful in Samba 2.2 only. Obsolete in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Causes Samba to serve domain logons. This is one of the basic functions required when Samba is acting
Reviews
as the PDC.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Makes Samba a domain master browser for its domain. When domain logons are enabled, domain
Reviews
master defaults to YES. Otherwise, it defaults to NO.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Prohibits a change directory or search in the directories specified. This is a browsing-convenience option;
Reviews
it doesn't provide any extra security.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Allows anyone with write permissions to change permissions on a file, as allowed by MS-DOS.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Errata
Sets file times on Unix to match MS-DOS standards (rounding to the next even second). Recommended if
Reviews
using Visual C++ or a PC make program to avoid remaking the programs unnecessarily. Use with the dos
Reader Reviews
filetimes option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Allows nonowners to change file times if they can write to the files, matching the behavior of MS-DOS
Reviews
and Windows. See also dosfiletimeresolution.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Reviews
Reader Reviews
Errata
If enabled, Samba will use password encryption. Requires an smbpasswd file on the Samba server.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Errata
Automatically synchronizes browse lists with all domain master browsers known to the WINS server.
Reviews
Makes cross-subnet browsing more reliable, but also can cause empty workgroups to persist forever in
Reader Reviews
browse lists.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Allows for a command to provide clients with customized MS-DOS/Windows port names (e.g., PRN:)
Reviews
corresponding to printers. Samba's default behavior is to return Samba Printer Port. The command
Reader Reviews
must return a series of lines, with one port name per line.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
exec = command
Table of Contents
Index
Reader Reviews
Errata
Sets a command to run as the user before connecting to the share. Synonym for preexec. See also the
Reviews
postexec,rootpreexec, and root postexec options.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
A bug fix for users of Microsoft nmake. If YES, Samba sets directory create times such that nmake won't
Reviews
remake all files every time.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Errata
If set, returns YES whenever a client asks if it can lock a file and cache it locally but does not enforce the
Reviews
lock on the server. Results in performance improvement for read-only shares. Never use with read/write
Reader Reviews
shares! See also
oplocks and vetooplockfiles.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set to YES, Samba follows symlinks in a file share(s). See the widelinks option if you want to restrict
Reviews
symlinks to just the current share.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
Takes effect when a user on a Windows client creates a file that resides on the Samba server. This option
Reviews
ensures that bits set in this mask will always be set on the new file. Used with the create mask
Reader Reviews
configuration option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
Takes effect when a user on a Windows client creates a directory on the Samba server. This option
Reviews
ensures that bits set in the mask will be set on every newly created directory. Used with directory
Reader Reviews
mask.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
Index
Errata
Takes effect when a user on a Windows client edits the Unix permissions of a directory on the Samba
Reviews
server. This option ensures that bits set in this mask will be set on the directory. Requires ntacl
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the effective group name assigned to all users accessing a share. Used to override a user's normal
Reviews
group memberships.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
Index
Errata
Takes effect when a user on a Windows client edits the Unix permissions of a file on the Samba server.
Reviews
This option ensures that bits set in the mask will always be set on the file. Requires ntaclsupport=
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
When set, unknown users or groups in Windows NT ACLs will be mapped to the user or group of the
Reviews
connected user. Obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the effective username assigned to all users accessing a share. Discouraged.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
fstype = string
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Caches the current directory for performance. Recommended with the widelinks option.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
group = value
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the name of the unprivileged Unix account to use for tasks such as printing and for accessing shares
Reviews
marked with guestok. The default is specified at compile time and is usually set to nobody.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
guest ok = boolean
Index
Reviews
Reader Reviews
Errata
If set to YES, doesn't need passwords for this share. Used with security = share. Synonym for public.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Forces users of a share to log on as the guest account. Requires guestok or public to be YES. Also
Reviews
called onlyguest.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Treats files with names beginning with a dot as if they had the MS-DOS hidden attribute set. The files are
Reviews
either not displayed on a Windows client or appear grayed-out, depending on the settings on the client.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies a list of file or directory names on which to set the MS-DOS hidden attribute. Names can contain
Reviews
? or * pattern characters and % variables. See also hidedotfiles and vetofiles.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If set to YES, hides Unix-specific dummy accounts (root,wheel,floppy, etc.) from clients.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Used with nishomedir to locate a user's Unix home directory from Sun NIS (not NIS+).
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Errata
If set to YES and Samba was configured with the --with-msdfs option, provides Microsoft Distributed
Reviews
filesystem (Dfs) service, allowing Dfs-capable clients to browse Dfs trees on the Samba server. See also
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies a list of systems that can access the share. If NULL, any system can access the share unless
Reviews
there is a hostsdeny option. Synonym for allowhosts.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a list of systems that cannot connect to the share. Synonym for denyhosts.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies the path to a file of trusted systems from which passwordless logons are allowed. Strongly
Reviews
discouraged because Windows NT/2000/XP users can always override the usernamethe only security in
Reader Reviews
this scheme.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
include = filename
Table of Contents
Index
Errata
Includes the named file in smb.conf at the line where it appears. This option accepts most variables, but
Reviews
not%u (user), %P (current share's root directory), or %S (current share's name) because they are not set
Reader Reviews
at the time the file is read.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
If set, files and subdirectories are created with the same ACLs as their parent directories. Directories are
Reviews
given Unix permissions of 0777 (full permissions) ensuring that the ACL on the directory will govern the
Reader Reviews
actual permissions given to clients. Requires POSIX ACL support to be provided on the Samba host
Errata
system.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
If set, files and subdirectories are created with the same permissions as their parent directories. This
Reviews
allows Unix directory permissions to be propagated automatically to new files and subdirectories,
Reader Reviews
especially in the
[homes] share. This option overrides createmask,directorymask,forcecreatemode,
Errata mode, but not map archive,map hidden, or map system. Samba never sets the
andforcedirectory
Using
Samba,
2nd Edition
setuid
bit when
creating a file or directory.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
Contents except 127.0.0.1)
Index
Sets the interfaces to which Samba will respond. The default is the system's primary interface only.
Reviews
Recommended on multihomed systems or to override erroneous addresses and netmasks. Allows
Reader Reviews
interface names
such as eth0, DNS names, address/netmask pairs, and broadcast/netmask pairs. See
Errata
alsobind interfaces
only.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
keepalive = number
[global]
Index
Errata
Sets the number of seconds between checks for a crashed client. The value of 0 causes no checks to be
Reviews
performed. Setting keepalive = 3600 will turn on checks every hour. A value of 600 (every 10 minutes)
Reader Reviews
is recommended
if you want more frequent checks. See also socketoptions for another approach.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Errata
Breaks the oplock when a local Unix process or NFS operation accesses an oplocked file, thus preventing
Reviews
corruption. This works only on operating systems that support kernel-based oplocks, such as Linux 2.4
Reviews
and Irix. AvoidReader
changing.
See also oplocks and level2oplocks.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set to YES, allows clients to use the (weak) LANMAN password hash used by Windows 95/98/Me. If set
Reviews
to NO, allows only the better NT1 hash used by Windows NT/2000/XP.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Reader Reviews
Errata
If set to YES, allows Windows 2000/XP to read and write 64KB at a time to improve performance.
Reviews
Requires Samba to be hosted by a 64-bit OS, such as Linux 2.4, Irix, or Solaris. Somewhat experimental.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Sets the Distinguished Name used by Samba when contacting the LDAP server. Requires Samba to be
Reviews
configured with the --with-ldapsam configuration option. Experimental option added in Samba 2.2.3 and
Reader Reviews
obsolete in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the LDAP search filter. Requires that Samba be configured with the --with-ldapsam configuration
Reviews
option. Experimental option added in Samba 2.2.3 and obsolete in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of2.2,
Contents
Index
Errata
Sets the TCP port number for contacting the LDAP server. Requires that Samba be configured with the -
Reviews
with-ldapsam configuration option. Experimental option added in Samba 2.2.3 and obsolete starting with
Reader Reviews
Samba 3.0. See
also ldap ssl.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the domain name of the LDAP server. Requires that Samba be configured with the --with-ldapsam
Reviews
configuration option. Experimental option added in Samba 2.2.3 and obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Sets whether Samba uses SSL to contact the LDAP server. ON and OFF turn SSL encryption on or off.
Reviews
The START TLS setting causes Samba to use LDAPv3 StartTLS extended operation. Requires that Samba
Reviews
be configured Reader
with the
--with-ldapsam configuration option. Experimental option added in Samba 2.2.3
Errata
andobsolete in Samba 3.0.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Sets the base Distinguished Name to use for LDAP searches. Requires that Samba be configured with the
Reviews
--with-ldapsam configuration option. Experimental option added in Samba 2.2.3 and obsolete in Samba
Reader Reviews
3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Allows files to be cached read-only on the client when multiple clients have opened the file. This allows
Reviews
executables to be cached locally, improving performance.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
lm announce = value
[global]
Table of Contents
Index
Errata
Produces OS/2 SMB broadcasts at an interval specified by the lminterval option. YES/NO turns them
Reviews
on/off unconditionally. AUTO causes the Samba server to wait for a LAN manager announcement from
Reader Reviews
another client before sending one out. Required for OS/2 client browsing.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
lm interval = number
[global]
Index
Reviews
Reader Reviews
Errata
Sets the time period, in seconds, between OS/2 SMB broadcast announcements.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Loads all printer names from the system's printcap file into the browse list. Uses configuration options
Reviews
from the [printers] section.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Allows Samba to participate in elections for the local master browser. See also domainmaster and os
Reviews
level.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets a directory in which to keep lock files. The directory must be writable by Samba and readable by
Reviews
everyone. Also called lockdir.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the number of attempts to attain a byte range lock. See also lock spin time.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Sets the number of microseconds between attempts to attain a lock. See also lockspincount.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
locking = boolean
Index
Reader Reviews
Errata
Performsfile locking. If set to NO, Samba accepts lock requests but won't actually lock resources. Turn
Reviews
off for read-only filesystems.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the name and location of the log file. Allows all % variables.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the logging level used. Values of 3 or more slow the system noticeably. Recommended value is 1.
Reviews
Synonym for debuglevel.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Sets the drive to be used as a home directory for domain logons by Windows NT/2000/XP clients. See
Reviews
alsologonhome.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Sets the home directory of a Windows 95/98/Me or NT/2000/XP user. Allows NETUSEH:/HOME from the
Reviews
command prompt if Samba is acting as a logon server. Append \profile or other directory to the value
Reader Reviews
of this parameter if storing Windows 95/98/Me profiles in a subdirectory of the user's home directory.
Errata
Seelogon path
for Windows NT/2000/XP roaming profiles.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Reader Reviews
Errata
Sets the path to the directory where Windows NT/2000/XP roaming profiles are stored. See also logon
Reviews
home for Windows 95/98/Me roaming profiles.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the pathname (relative to the [netlogon] share) of an MS-DOS/NT command to run on the client at
Reviews
logon time. Allows all % variables.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the command to pause a print job. Honors the %p (printer name) and %j (job number) variables.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the command used to get printer status. Usually initialized to a default value by the printing
Reviews
option. Honors the %p (printer name) variable.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the command to resume a paused print job. Honors the %p (printer name) and %j ( job number)
Reviews
variables.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the command to delete a print job. Usually initialized to a default value by the printing option.
Reviews
Honors the %p (printer name) and %j (job number) variables.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table(1
of week)
Contents
Index
Reviews
Reader Reviews
Errata
Sets the period between (NT domain) computer account password changes.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the output file for the magicscripts option. Default is the command name, followed by the .out
Reviews
extension.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
Sets a filename for execution via a shell whenever the file is closed from the client, allowing clients to run
Reviews
commands on the server. The scripts will be deleted on completion, if permissions allow. Use is
Reader Reviews
discouraged.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Sets Samba to abbreviate to the MS-DOS 8.3 style names that are too long or have unsupported
Reviews
characters.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Sets the algorithm used to mangle filenames. The hash2 method is a newer method introduced in Samba
Reviews
2.2.x, and it creates different filenames than the hash method.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If YES, Samba sets the executable-by-user (0100) bit on Unix files if the MS-DOS archive attribute is set.
Reviews
If used, the createmask must contain the 0100 bit.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If YES, Samba sets the executable-by-other (0001) bit on Unix files if the MS-DOS hidden attribute is set.
Reviews
If used, the create mask option must contain the 0001 bit.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If YES, Samba sets the executable-by-group (0010) bit on Unix files if the MS-DOS system attribute is
Reviews
set. If used, the createmask must contain the 0010 bit.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
If set to Bad User, allows users without accounts on the Samba system to log in and be assigned the
Reviews
guest account. This option can be used as part of making public shares for anyone to use. If set to Bad
Reader Reviews
Password, users who mistype their passwords will be logged in to the guest account instead of their own.
Errata
Because no warning
is given, the Bad Password value can be extremely confusing: we recommend
Using Samba, 2nd Edition
against it. The default setting of Never prevents users without accounts from logging in.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the maximum number of share connections allowed from each client system.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Reader Reviews
Errata
Sets the maximum disk size/free-space size (in megabytes) to return to the client. Some clients or
Reviews
applications can't understand large maximum disk sizes.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Sets the size (in kilobytes) at which Samba will start a new log file. The current log file will be renamed
Reviews
with a .old extension, replacing any existing file with that name.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Sets the number of simultaneous SMB operations that Samba clients can make. Avoid changing.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Limits the number of files a Samba process will try to keep open at one time. Samba allows you to set
Reviews
this to less than the maximum imposed by the Unix host operating system. Avoid changing.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Limits the number of jobs that can be in the queue for this printer share at any one time. The printer will
Reviews
reportout of space if the limit is exceeded. See also total print jobs.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If set, limits the negotiation to the protocol specified, or older. See min protocol. Avoid using.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Reader Reviews
Errata
Limits the number of users who can connect to the server. Used to prevent degraded service under an
Reviews
overload, at the cost of refusing services entirely.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table(3
of days)
Contents
Index
Reviews
Reader Reviews
Errata
Sets the time to live (TTL) of NetBIOS names in the nmbd WINS cache. Avoid changing.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table(6
of days)
Contents
Index
Reader Reviews
Errata
Limits the TTL, in seconds, of a NetBIOS name in the nmbd WINS cache. Avoid changing. See also min
Reviews
wins ttl.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the maximum packet size negotiated by Samba. This is a tuning parameter for slow links and bugs
Reviews
in older clients. Values less than 2048 are discouraged.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Sets the command to run on the server when a WinPopup message arrives from a client. If it does not
Reviews
complete quickly, the command must end in & to allow immediate return. Honors all % variables except %u
Reader Reviews
(user) and supports
the extra variables %s (filename the message is in), %t (destination system), and %f
Errata
(from).
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the shortest Unix password allowed by Samba when updating a user's password on its system. Also
Reviews
called minpasswdlength.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the minimum spool space required before accepting a print request.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
If set, prevents use of old (less secure) protocols. Using NT1 disables MS-DOS clients. See also lanman
Reviews
auth.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
Contents
Index
Reviews
Reader Reviews
Errata
Sets the minimum TTL, in seconds, of a NetBIOS name in the nmbd WINS cache. Avoid changing.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Makes the share a Dfs root. Requires the --with-msdfs configure option. Any symbolic links of the form
Reviews
msdfs:server\share will be seen as Dfs links. See also host msdfs.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of
Contents
Index
Reader Reviews
Errata
Sets the order of lookup when trying to get IP addresses from names. The host parameter carries out a
Reviews
regular name lookup using the server's normal sources: /etc/hosts, DNS, NIS, or a combination of these.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Adds additional NetBIOS names by which the Samba server will advertise itself.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
Index
Reader Reviews
Errata
Sets the NetBIOS name by which a Samba server is known, or the primary name if NetBIOS aliases exist.
Reviews
See also netbios aliases.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the NetBIOS scope string, an early predecessor of workgroups. Samba will not communicate with a
Reviews
system with a different scope. This option is not recommended.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
If YES, the homedirmap is used to look up the server hosting the user's home directory and return it to
Reviews
the client. The client will contact that system to connect to the share. This avoids mounting from a
Reader Reviews
system that doesn't actually have the directory, which would cause the data to be transmitted twice. The
Errata
system with the
home directories must be an SMB server.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies a range of Unix UIDs for Samba to use for user accounts and computer accounts that are
Reviews
maintained outside of /etc/passwd. The UIDs in this range must not overlap those of regular Unix users
Reviews
in /etc/passwd.Reader
See also
algorithmic rid base. New in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Allows turning off of NT-specific pipe calls. This is a developer/benchmarking option and might be
Reviews
removed in the future. Avoid changing.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If YES, allows the use of NT-specific SMBs. This is a developer/benchmarking option that is obsolete in
Reviews
Samba 3.0. Avoid changing.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If YES, allows the use of NT-specific status messages. This is a developer/benchmarking option and
Reviews
might be removed in the future. Avoid changing.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If YES, allows access to accounts that have null passwords. Strongly discouraged.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set, Samba will adhere to the PAM's account and session restrictions. Requires --with-pam
Reviews
configuration option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Forces users of a share to log on as the guest account. Synonym for guestonly. Requires guestok or
Reviews
public to be YES.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Requires that users of the share be in the list specified by the user option.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
This is an advanced tuning parameter and is recommended only for experts who know how Samba
Reviews
handles oplocks. This option might need to be set if a Windows system fails to release an oplock in
Reader Reviews
response to a break request from the Samba server. Due to bugs on some Windows systems, they might
fail to respondErrata
if Samba responds too quickly; the default on this option can be lengthened in such cases.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
This is an advanced tuning parameter and is recommended only for experts who know how Samba
Reviews
handles oplocks. It causes Samba to refuse to grant an oplock if the number of clients contending for a
Reader Reviews
file exceeds the specified value.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
oplocks = boolean
Index
Reader Reviews
Errata
If YES, supports local caching of oplocked files on the client. This option is recommended because it
Reviews
improves performance by about 30%. See also fakeoplocks and vetooplockfiles.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
os level = number
[global]
Index
Sets the candidacy of the server when electing a browse master. Used with the domainmaster or local
Reviews
master options. You can set a higher value than a competing operating system if you want Samba to win.
Reader Reviews
Windows for Workgroups and Windows 95/98/Me use 1. Windows NT/2000/XP, when not acting as a
Errata
PDC, use 16 and,
when acting as a PDC, use 32. Warning: this can override non-Samba browse masters
Using Samba, 2nd Edition
unexpectedly.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a file containing mappings of Windows NT printer driver names to OS/2 printer driver names.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If YES, and if Samba is configured with --with-pam, PAM is allowed to handle password changes from
Reviews
clients, instead of using the program defined by the passwdprogram parameter.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the command to run when Samba panics. Honors all % variables. For Samba developers and testers,
Reviews
/usr/bin/X11/xterm-display:0-egdb/samba/bin/smbd%d is a possible value.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies methods Samba uses to store and retrieve passwords when using a method other than the Unix
Reviews
system's/etc/passwd. See also non unix account range. New in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Sets the chat strings used to change passwords on the server. Supports the variables %o (old password)
Reviews
and%n (new password) and allows the escapes \r,\n,\t, and \s (space) in the sequence. See also unix
Reader Reviews
password sync,
passwd program,passwd chat debug, and pampassword change.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Logs an entire password chat, including passwords passed, with a log level of 100. For debugging only.
Reviews
See also passwd chat,pam password change, and passwd program.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the command used to change a user's password. Will be run as root. Supports %u (user). See also
Reviews
unix password sync.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Specifies the number of uppercase-letter permutations used to match passwords. A workaround for
Reviews
clients that change passwords to a single case before sending them to the Samba server. Causes
Reader Reviews
repeated login attempts with mixed-case passwords, which can trigger account lockouts. Required for
Errata
Windows 95/98/Me,
plain-text passwords, and mixed-case passwords. Try to avoid using.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Specifies a list of SMB servers that validate passwords. Used with a Windows NT/2000 password server
Reviews
(PDC or BDC) and the security=server or security=domain configuration options. Caution: a
Reader Reviews
Windows NT/2000
password server must allow logins from the Samba server. If set to *, Samba will look
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
path = directory
Table of Contents
Index
Errata
Sets the path to the directory provided by a file share or used by a printer share. If the option is omitted,
Reviews
it is set automatically in the [homes] share to the user's home directory; otherwise, defaults to /tmp.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the path to the directory where PID files are located.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
If set to YES, Samba will map file locks owned by SMB clients to POSIX locks. Avoid changing.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
postexec = command
Table of Contents
Index
Reader Reviews
Errata
Sets a command to run as the user after disconnecting from the share. See also the preexec,root
Reviews
preexec, and rootpostexec options.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
postscript = boolean
Index
Reader Reviews
Errata
Forces a printer to recognize a file as PostScript by inserting %! as the first line. Works only if the printer
Reviews
is actually PostScript-compatible.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
preexec = command
Table of Contents
Index
Reader Reviews
Errata
Sets a command to run as the user before connecting to the share. Synonym for exec. See also the
Reviews
postexec,rootpreexec, and rootpostexec options.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set, allows the preexec command to decide if the share can be accessed by the user. If the command
Reviews
returns a nonzero return code, the user is denied permission to connect.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If YES, Samba is the preferred master browser. Causes Samba to call a browsing election when it comes
Reviews
online. See also os level.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies a list of shares that always appears in browse lists. Synonym for autoservices. See also load
Reviews
printers.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
Leaves filenames in the case sent by the client. If NO, it forces filenames to the case specified by the
Reviews
defaultcase option. See also shortpreservecase.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
printable = boolean
Index
Reviews
Reader Reviews
Errata
Sets a share to be a print share. Required for all printers. Synonym for printok.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the path to the printer capabilities file used by the [printers] share. The default value changes to
Reviews
/etc/qconfig under AIX and lpstat on System V. Also called printcap.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Errata
Sets the command used to send a spooled file to the printer. Usually initialized to a default value
Reviews
corresponding to the printing option. This option honors the %p (printer name), %s (spool file), and %f
Reader Reviews
(spool file as a relative path) variables. The command must delete the spool file.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
printer = name
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the name of the Unix printer used by the share. Also called printername.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies users who can administer a printer using the remote printer administration interface on a
Reviews
Windows system. The root user always has these privileges.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the string to pass to Windows when asked which driver to use to prepare files for a printer share.
Reviews
Note that the value is case-sensitive. Part of pre-2.2 printing system. Deprecated.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the location of a msprint.def file. Usable by Windows 95/98/Me. Part of pre-2.2 printing system.
Reviews
Deprecated.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of
Contents
Index
Reader Reviews
Errata
Sets the location of the driver for a particular printer. The value is the pathname of the share that stores
Reviews
the printer driver files. Part of pre-2.2 printing system. Deprecated.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
printing = value
Allowable values: bsd, sysv, hpux, aix, qnx, plp, softq, lprng, cups
Default:
bsd Table of Contents
Index
Reader Reviews
Errata
Sets the printing style to a value other than that in which you've compiled. This sets initial values of at
Reviews
leastprintcommand , lpqcommand , and lprmcommand.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
print ok = boolean
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies the directory used for storing security-sensitive files such as smbpasswd and secrets.tdb. New
Reviews
in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
protocol = name
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
public = boolean
Index
Reviews
Reader Reviews
Errata
If YES, passwords are not needed for this share. Also called guestok.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the command used to pause a print queue. Usually initialized to a default value by the printing
Reviews
option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets the command used to resume a print queue. Usually initialized to a default value by the printing
Reviews
option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
If set to YES, supports the "Read Block Multiplex" message. Avoid changing.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Allows disk reads and writes to overlap network reads and writes. A tuning parameter. Do not set larger
Reviews
than the default.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
realm = string
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies the realm name for Kerberos 5 authentication. Requires the --with-krb5 configure option. New
Reviews
in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Adds workgroups to the list on which the Samba server will announce itself. Specified as an IP address
Reviews
and optional workgroup (for instance, 192.168.220.215/SIMPLE) with multiple entries separated by
Reader Reviews
spaces. Addresses can be the specific address of the browse master on a subnet or on directed
Errata
broadcasts (i.e.,
###.###.###.255). The server will appear on those workgroups' browse lists. Does
Using Samba, 2nd Edition
not require WINS.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Perform browse list synchronization with other Samba local master browsers. Addresses can be specific
Reviews
addresses or directed broadcasts (i.e., ###.###.###.255). The latter causes Samba to locate the local
Reader Reviews
master browser on that subnet.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Denies access to users who do not supply a username. This is disabled by default because when the
Reviews
Samba server acts as the domain's PDC, the option can keep a client from revalidating its computer
Reader Reviews
account when someone new logs in. Use of the option is recommended only when all clients are Windows
Errata
NT/2000/XP systems.
Using Samba, 2nd Edition
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
root = directory
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies a directory to chroot( ) before starting daemons. Prevents any access outside that directory
Reviews
tree. See also the widelinks configuration option. Also called root and rootdir.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets a command to run as root after disconnecting from the share. See also the preexec,postexec, and
Reviews
rootpreexec configuration options. Runs after the user's postexec command. Use with caution.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets a command to run as root before connecting to the share. See also the preexec,postexec, and
Reviews
rootpostexec configuration options. Runs before the user's preexec command. Use with caution.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set, allows the rootpreexec command to decide if the share can be accessed by the user. If the
Reviews
command returns a nonzero return code, the user will be denied permission to connect.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
security = value
[global]
Index
Sets the client authentication method. If security=share, services are password-protected, available to
Reviews
everyone who knows the password. If security=user, users have accounts and passwords, and are
Reader Reviews
required to authenticate
with the server before accessing services. If security=server, users have
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Controls which permission bits can be changed if a user on a Windows NT/2000/XP system edits the Unix
Reviews
permissions of files on the Samba server using the Windows system's ACL editing dialog box. Any bit that
Reader Reviews
is set in the mask can be changed by the user; any bit that is clear remains the same on the file even if
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
Index
Reader Reviews
Errata
Sets the name that corresponds to the Samba server in browse lists. Honors the %v (Samba version
Reviews
number) and %h (hostname) variables.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Allows the DEC Pathworks client to use the set dir command.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
Directs Samba to support Windows-style whole-file (deny mode) locks. Do not change.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set to YES, leaves mangled 8.3-style filenames in the case sent by the client. If NO, forces the case to
Reviews
that specified by the defaultcase option. See also preservecase.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set, tells clients that the Add Printer Wizard can be used to add a Samba printer from Windows
Reviews
NT/2000/XP clients. See also add printer command,delete printercomamnd, and printer admin.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies a command that initiates a system shutdown. The command is run with the UID of the
Reviews
connected user. The %m (message), %t (delay time), %r (reboot), and %f (force) options are supported.
Reader Reviews
See also abort
shutdown script. New in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Overrides the compiled-in path to the encrypted password file. See also encryptedpasswords and
Reviews
private dir.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the address on which to listen for connections. Default is to listen to all addresses.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Sets OS-specific socket options. SO_KEEPALIVE makes TCP check clients every four hours to see if they
Reviews
are still accessible. TCP_NODELAY sends even tiny packets to keep delay low. Both are recommended
Reader Reviews
wherever the operating system supports them.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Causes Samba to read a list of environment variables from a file upon startup. This can be useful when
Reviews
setting up Samba in a clustered environment. The filename can begin with a "|" (pipe) character, in which
Reader Reviews
case it causes Samba to run the file as a command to obtain the variables.
Using
Samba,
The file
must2nd
beEdition
owned
by root and must not be world-writable. If the filename begins with a "|"
character,
it must point
toEckstein
a command
By
David Collier-Brown
, Robert
, Jay Ts that is neither world-writable nor resides in a world-writable
directory.
Publisher: O'Reilly
The data should be in the form of lines such as SAMBA_NETBIOS_NAME=myhostname. This value will then
Pub Date: February 2003
be available in the smb.conf files as %$SAMBA_NETBIOS_NAME.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
ssl = boolean
[global]
Index
Reader Reviews
Errata
Makes Samba use SSL for data exchange with some or all hosts. Requires --with-ssl configure
Reviews
option.Obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies a directory containing a file for each Certification Authority (CA) that the Samba server trusts so
Reviews
that Samba can verify client certificates. Part of SSL support. Requires --with-ssl configure option.
Reader Reviews
Obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies a file that contains information for each CA that the Samba server trusts so that Samba can
Reviews
verify client certificates. Part of SSL support. Requires --with-ssl configure option. Obsolete starting
Reader Reviews
with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies which ciphers should be offered during SSL negotiation. Not recommended. Requires --with
Reviews
ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies a file containing the server's SSL certificate, for use by smbclient if certificates are required in
Reviews
this environment. Requires --with-ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies a file containing the server's private SSL key, for use by smbclient. Requires --with-ssl
Reviews
configure option. Obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Determines whether SSLeay should be configured for bug compatibility with other SSL implementations.
Reviews
Not recommended. Requires --with-ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Requires that SSL be used with the hosts listed. By default, if the ssl option is set, the server requires
Reviews
SSL with all hosts. Requires --with-ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Suppresses the use of SSL with the hosts listed. By default, if the ssl option is set, the server requires
Reviews
SSL with all hosts. Requires --with-ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Requires clients to use certificates when SSL is in use. This option is recommended if SSL is used.
Reviews
Requires--with-ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
When SSL is in use, smbclient requires servers to use certificates. This option is recommended if SSL is
Reviews
used. Requires --with-ssl configure option. Obsolete starting with Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies a file containing the server's SSL certificate. Requires --with-ssl configure option. Obsolete
Reviews
starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Specifies a file containing the server's private SSL key. If no file is specified and SSL is in use, the server
Reviews
looks up its key in its server certificate. Requires --with-ssl configure option. Obsolete starting with
Reader Reviews
Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
Defines which versions of the SSL protocol the server can use: Version 2 only ("ssl2"), Version 3 only
Reviews
("ssl3"), Version 2 or 3 dynamically negotiated ("ssl2or3"), or Transport Layer Security ("tls1"). Requires
Reader Reviews
--with-ssl configure
option. Obsolete starting with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Makes the Samba server cache client names for faster resolution. Should not be changed.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Determines the number of client names cached for faster resolution. Should not be changed.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
status = boolean
[global]
Index
Reader Reviews
Errata
If set to YES, logs connections to a file (or shared memory) accessible to smbstatus.Obsolete starting
Reviews
with Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Errata
If set to YES, allocates all disk blocks when creating or extending the size of files, instead of using the
Reviews
normal sparse file allocation used on Unix. This slows the server, but results in behavior that matches
Reader Reviews
that of Windows and helps Samba correctly report "out of quota" messages.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
If set to YES, checks locks on every access, not just on demand and at open time. Not recommended.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Errata
If set to YES, Samba synchronizes to disk whenever the client sets the sync bit in a packet. If set to NO,
Reviews
Samba flushes data to disk whenever buffers fill. Defaults to NO because Windows 98 Explorer sets the
Reader Reviews
bit (incorrectly) in all packets.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Removes trailing dots from filenames. Dysfunctional in Samba 2.2; use mangledmap instead.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
Errata
If set to YES, Samba forces the data to disk through fsync (3) after every write. Avoid except to debug
Reviews
crashing servers.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
syslog = number
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the level of Samba log messages to send to syslog. Higher is more verbose. The syslog.conf file
Reviews
must have suitable logging enabled.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If set to YES, logs only to syslog instead of the standard Samba log files.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the home directory for Unix login sessions for users authenticated through winbind. %D will be
Reviews
replaced with user's domain name; %U by the username.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the shell for Unix login sessions for users authenticated through winbind. The default value prevents
Reviews
all Windows domain user logins.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the number of minutes to add to the system time-zone calculation. Provided to fix a client daylight
Reviews
savings bug. Not recommended.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set to YES, nmbd advertises itself as a provider of SMB time service to clients. This option only affects
Reviews
whether the time service is advertised. It does not enable or disable time service.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table
of Contents
Index
Reviews
Reader Reviews
Errata
Limits total number of current print jobs on server. See also max print jobs.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set to YES, supports CIFS Unix extensions, providing better filesystem support for Unix clients.
Reviews
Obsolete in Samba 3.0, which always offers support.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Errata
If set to YES, attempts to change the user's Unix password whenever the user changes her SMB
Reviews
password. Used to ease synchronization of Unix and Microsoft password databases. See also password
Reader Reviews
program and passwd
chat.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
Updates the encrypted password file when a user logs on with an unencrypted password. Provided to
Reviews
ease conversion from unencrypted to encrypted passwords.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Errata
Used for avoiding Access Denied; Unable to connect messages when connecting to a Samba printer
Reviews
from Windows NT/2000/XP clients. Necessary only when the client has a local printer driver for the
Reader Reviews
Samba printer.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Tells Samba whether the mmap( ) system call works correctly on the Samba host. Default is
Reviews
automatically set correctly. Do not change.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set to YES, users' ~/.rhosts files will be used to identify systems from which users can connect without
Reviews
providing a password. Discouraged. Obsolete in Samba 3.0.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
If yes, Samba will perform some data transfers for exclusively oplocked files using the sendfile( ) system
Reviews
call, which results in significant performance improvements. This is available if Samba has been
Reader Reviews
configured with
the --with-sendfile-support option. This is an experimental option and is new in
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Sets a list of users that are tried when logging on with share-level security in effect. Also called user or
Reviews
users. Discouraged. Use NETUSE\\server\share %user from the client instead.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Specifies the number of uppercase-letter permutations allowed to match Unix usernames. A workaround
Reviews
for Windows' single-case usernames. Use is discouraged.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reader Reviews
Errata
Names a file of Unix-to-Windows name pairs; used to map different spellings of account names and
Reviews
Windows usernames longer than eight characters.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
utmp = boolean
[global]
Index
Errata
This is available if Samba has been configured with the --with-utmp option. If set, Samba adds
Reviews
utmp/utmpx records whenever a connection is made to a Samba server. Sites can use this option to
Reader Reviews
record each connection to a Samba share as a system login.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Errata
This is available if Samba has been configured with the --with-utmp option. If this option and utmp are
Reviews
set, Samba will look in the specified directory rather than the default system directory for utmp/utmpx
Reader Reviews
files.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Adds national characters to a character set map. See also clientcodepage.Obsolete in Samba 3.0.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table
of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a list of users that can connect to a share. See also invalid users.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies a list of files that the client will not see when listing a directory's contents. See also deleteveto
Reviews
files and hide files.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a list of files not to oplock (and cache on clients). See also oplocks and fakeoplocks.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata
Specifies the shared library to use for Samba's Virtual File System (VFS). Requires the --with-vfs
Reviews
configure option.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies parameters to the VFS. Requires the --with-vfs configure option. See vfs object.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
volume = string
Table of Contents
Index
Reviews
Reader Reviews
Errata
Sets the volume label of a disk share. Especially useful with shared CD-ROMs.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Index
Reviews
Reader Reviews
Errata
If set, Samba follows symlinks out of the disk share. See also the rootdir and followsymlinks options.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Sets the amount of time that the winbindd daemon caches user and group information.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies the group ID range winbind uses for Windows NT domain users connecting to Samba.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies the character winbind uses to separate a domain name and username.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies the user ID range winbind will use for Windows NT domain users connecting to Samba.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Specifies a command to run whenever the WINS server updates its database. Allows WINS to be
Reviews
synchronized with DNS or other services. The command is passed one of the arguments add,delete, or
Reader Reviews
refresh, followed
by the NetBIOS name, the name type (two hexadecimal digits), the TTL in seconds,
Errata
and the IP addresses
corresponding to the NetBIOS name. Requires winsservice=YES.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reader Reviews
Errata
If set to YES, nmbd proxies resolution requests to WINS servers on behalf of old clients, which use
Reviews
broadcasts. The WINS server is typically on another subnet.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
If set to YES, activates the WINS service. The winsserver option must not be set if winssupport=YES.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
workgroup = name
[global]
Table of Contents
Index
Reader Reviews
Errata
Sets the workgroup or domain to which the Samba server belongs. Overrides the compiled-in default of
Reviews
WORKGROUP. Choosing a name other than WORKGROUP is highly recommended.
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
writable = boolean
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
writeable = boolean
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Allocates a write buffer of the specified size in which Samba accumulates data before a write to disk. This
Reviews
option can be used to ensure that each write has the optimal size for a given filesystem. It is typically
Reader Reviews
used with RAID drives, which have a preferred write size, and with systems that have large memory and
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Specifies a list of users that are given read/write access to a read-only share. See also readlist.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
write ok = boolean
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[global]
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reader Reviews
Errata or compiled program, with an absolute path specified for the executable and
A Unix script
Using Samba,
2nd Edition
parameters.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
directory
Pages:
556
An absolute
/etc/printcap
Slots: 1
host list
A list of hosts. Allows IP addresses, address masks, domain names, ALL, and EXCEPT.
interface
list Second Edition is a comprehensive guide to Samba administration. This new edition covers
Using Samba,
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
A list of interfaces, in either address/netmask or address/n-bits format. For example:
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
192.168.2.10/255.255.255.0, 192.168.2.10/24
Samba's new role as a primary domain controller and domain member server, its support for the use of
map list
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
sharedAfiles
and
printersremapping
from Unixstrings
clients.such as (*.html*.htm).
list of
filename
name
A single name of a type of object, as specified in the option's description.
number
A positive integer.
numeric range
Two numbers separated by a dash, specifying a minimum and a maximum value. For example:
100-250
remote list
A list of subnet-broadcast-address/workgroup pairs. For example:
192.168.2.255/SERVERS 192.168.4.255/STAFF
service (share) list
A list of service (share) names, without the enclosing parentheses.
slash-separated list
A list of filenames, separated by "/" characters to allow embedded spaces. For example:
/.*/My Documents/*.doc/
string
One line of arbitrary text.
user list
A list of usernames and/or group names. @group_name includes whomever is in the NIS netgroup
group_name, if one exists, or otherwise whomever is in the Unix group group_name. In addition,
+group_name is a Unix group, &group_name is an NIS netgroup, and &+ and +& cause an ordered
search of both Unix and NIS groups.
value
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Name
Errata
%a
%d
%D
Publisher: O'Reilly
%f
%f
spool
ISBN:Printer
0-596-00256-4
Pages: 556
Slots: 1
%G
%g
%H Samba,
Home
directory
of %u
(actual
username)guide to Samba administration. This new edition covers
Using
Second
Edition
is a
comprehensive
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
%h
Samba server's (Internet) hostname
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new
role as
a primary domain controller and domain member server, its support for the use of
%I
Client's
IP address
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
%j
number
(printing
only)
shared
filesPrint
and job
printers
from
Unix clients.
%L
%M
%m
%N
Name of the NIS home directory server (without NIS, same as %L)
%n
%o
%P
%p
%p
%R
%S
%s
%s
%T
%t
%U
%u
%v
Samba version
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents listing of command-line options and other information to help you use the
programs
that
come
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
smbd
Thesmbd program provides Samba's file and printer services, using one TCP/IP stream and one daemon
per client. It is controlled from /usr/local/samba/lib/smb.conf , the default configuration file, which can be
overridden byTable
command-line
of Contents options.
Index
The
configuration
file is automatically reevaluated every minute. If it has changed, most new options are
Reviews
immediately effective. You can force Samba to reload the configuration file immediately by sending a
Reader Reviews
SIGHUP signal to smbd. Reloading the configuration file does not affect any clients that are already
Errata
connected. To escape this condition, a client would need to disconnect and reconnect, or the server itself
Using Samba, 2nd Edition
would have to be restarted, forcing all clients to reconnect.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher:
O'Reilly
Other
Signals
Pub Date: February 2003
ISBN:
0-596-00256-4
To shut
down
an smbd process, send it the termination signal SIGTERM (15), which allows it to die
gracefully,
of a SIGKILL (9). With Samba versions prior to 2.2, the debugging level could be
Pages: instead
556
raised Slots:
or lowered
using
SIGUSR1 or SIGUSR2. This is no longer supported. Use smbcontrol instead.
1
Command synopsis
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
smbd
[options]
all versions
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role as a primary domain controller and domain member server, its support for the use of
Options
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
-a
Causes each new connection to the Samba server to append all logging messages to the log file.
This option is the opposite of -o and is the default.
-D
Runs the smbd program as a daemon. This is the recommended way to use smbd. It is also the
default action when smbd is run from an interactive command line. In addition, smbd can be run
frominetd.
-ddebug_level
Sets the debug (sometimes called logging) level. The level can range from 0 to 10. Specifying the
value on the command line overrides the value specified in the smb.conf file. Debug level 0 logs
only the most important messages; level 1 is normal; levels 3 and above are primarily for
debugging and slow smbd considerably.
-h
Prints usage information for the smbd command.
-i
Runssmbd interactively, rather than as a daemon. This option is used to override the default
daemon mode when smbd is run from the command line.
-llog_ directory
Sends the log messages to somewhere other than the location compiled into the executable or
specified in the smb.conf file. The default is often /usr/local/samba/var/,/usr/samba/var/, or
/var/log/. The log file is placed in the specified directory and named log.smbd. If the directory does
not exist, Samba's compiled-in default will be used.
-Osocket_options
Sets the TCP/IP socket options, using the same parameters as the socket options configuration
Sets the TCP/IP port number from which the server will accept requests. All Microsoft clients send
Table ofport
Contents
to the default
of 139, except for Windows 2000/XP, which can use port 445 for SMB
networking,
Indexwithout the NetBIOS protocol layer.
-P
Reviews
Reader Reviews
Causessmbd
Errata to run in "passive" mode, in which it just listens, and does not transmit any network
traffic.
This
is useful only for debugging by developers.
Using Samba, 2nd Edition
-sconfiguration_ file
Specifies the location of the Samba configuration file. Although the file defaults to
you can override it on the command line. Typically used for
Pubdebugging.
Date: February 2003
Publisher:
O'Reilly
/usr/local/samba/lib/smb.conf
,
-v
ISBN: 0-596-00256-4
Pages: 556
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
nmbd
Thenmbd program is Samba's NetBIOS name service and browsing daemon. It replies to NetBIOS over
TCP/IP (also called NetBT or NBT) name-service requests broadcast from SMB clients, and optionally to
Microsoft's Windows
Table of Internet
Contents Name Service (WINS) requests. Both are versions of the name-to-address
lookup required
by SMB clients. The broadcast version uses UDP broadcast on the local subnet only,
Index
while
WINS uses
TCP, which can be routed. If running as a WINS server, nmbd keeps a current name
Reviews
and
address
database
in the file /usr/local/samba/var/locks/wins.dat.
Reader Reviews
Errata
An active nmbd daemon also responds to browsing protocol requests used by the Windows Network
Using Samba, 2nd Edition
Neighborhood. This protocol provides a dynamic directory of servers, as well as the disks and printers
By
David
Eckstein
, Jay
Ts WINS, this was initially done by making UDP broadcasts on the
that
theCollier-Brown
servers are,Robert
providing.
As
with
local subnet. With the addition of the local master browser to the network architecture, it is done by
making
TCPO'Reilly
connections to a server. If nmbd is acting as a local master browser, it stores the browsing
Publisher:
database
in
the
file2003
/usr/local/samba/var/locks/browse.dat.
Pub Date: February
ISBN: 0-596-00256-4
Some clients (especially older ones) cannot use the WINS protocol. To support these clients, nmbd can
Pages: 556
act as a WINS proxy, accepting broadcast requests from the non-WINS clients, contacting a WINS server
Slots: 1
on their
behalf, and returning the WINS server's response to them.
Signals
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Likesmbd, the nmbd program responds to several Unix signals. Sending nmbd a SIGHUP signal causes it
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
to dump the names it knows about to the /usr/local/samba/var/locks/namelist.debug file. To shut down
Samba's new role as a primary domain controller and domain member server, its support for the use of
annmbd process and allow it to die gracefully, send it a SIGTERM (15) signal, rather than a SIGKILL (9).
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
With Samba versions prior to 2.2, the debugging level could be raised or lowered using SIGUSR1 or
shared files and printers from Unix clients.
SIGUSR2. This is no longer supported. Use smbcontrol instead.
Command synopsis
nmbd[options]
Options
-a
Causes each new connection to the Samba server to append all logging messages to the log file.
This option is the opposite of -o and is the default.
-ddebug_level
Sets the debug (sometimes called logging) level. The level can range from 0 to 10. Specifying the
value on the command line overrides the value specified in the smb.conf file. Debug level 0 logs
only the most important messages; level 1 is normal; levels 3 and above are primarily for
debugging and slow nmbd considerably.
-D
Instructs the nmbd program to run as a daemon. This is the recommended way to use nmbd and is
the default when nmbd is run from an interactive shell. In addition, nmbd can be run from inetd.
-h
Prints usage information for the nmbd command.
-Hlmhosts_ file
Specifies the location of the lmhosts file for name resolution. This file is used only to resolve names
for the local server, and not to answer queries from remote systems. The compiled-in default is
commonly/usr/local/samba/lib/lmhosts,/usr/samba/lib/lmhosts, or /etc/lmhosts.
-i
Runsnmbd interactively, rather than as a daemon. This option is used to override the default
daemon mode when nmbd is run from the command line.
-llog_ file
Sends the log messages to somewhere other than the location compiled into the executable or
specified in the smb.conf file. The default is often /usr/local/samba/var/log.nmbd,
Table of Contents
/usr/samba/var/log.nmbd
, or /var/log /log.nmbd .
NetBIOS_name
-n
Index
Reviews
Allows you
to override
Reader
Reviews the NetBIOS name by which the daemon advertises itself. Specifying this
option on
the command line overrides the netbios name option in the Samba configuration file.
Errata
-O
socket_options
Using
Samba, 2nd Edition
ByDavidSets
Collier-Brown
, Robert
Eckstein
, Jay Tsusing
the TCP/IP
socket
options,
-o
Publisher: O'Reilly
Pub Date: February 2003
Causes
log files to be overwritten when opened (the opposite of -a). This option saves you from
ISBN: 0-596-00256-4
hunting
for the right log entries if you are performing a series of tests and inspecting the log file
Pages: 556
each time.
Slots: 1
-pport_number
Sets the UDP port number from which the server accepts requests. Currently, all Microsoft clients
use only the default port, 137.
Using
Samba, Second
Edition is a comprehensive guide to Samba administration. This new edition covers
-sconfiguration_
file
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
Updated
for Windows
2000, ME,
the book
Specifies
the location
of the tool.
Samba
configuration
file. Although
theand
fileXP,
defaults
to also explores
Samba's
new role as a primary domain
controller
and domain
member
server, its
support
for the
use
/usr/local/samba/lib/smb.conf
, you
can override
it here on
the command
line.
Typically
used
forof
Windows
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
debugging.
shared files and printers from Unix clients.
-v
Prints the current version of Samba.
winbindd
Thewinbindd daemon is part of the winbind service and is used to allow Unix systems to obtain user and
group information from a Windows NT/2000 server. Winbind maps Windows relative IDs (RIDs) to Unix
UIDs and GIDs
andofallows
accounts stored on the Windows server to be used for Unix authentication. Its
Table
Contents
purpose is to ease
Index integration of Microsoft and Unix networks when a preexisting Windows domain
controller
is set
up to handle user and computer accounts.
Reviews
Reader Reviews
The daemon is accessed by users via the name service switch and PAM. The name service switch calls a
Errata
library (/lib/libnss_winbind.so), which calls the daemon, which in turn calls the Windows NT/2000 server
Using Samba, 2nd Edition
using Microsoft RPC. The PAM module for winbind can call the daemon similarly, allowing users whose
By
David Collier-Brown
Eckstein
, Jay Ts
accounts
are stored,Robert
on the
Windows
server to log in to the Unix system and run an interactive shell, FTP,
or any other program that authenticates users through PAM.
Publisher: O'Reilly
ThePub
winbind
subsystem is currently available only for the Linux operating system and a few other
Date: February 2003
systems that use shared libraries, nsswitch and PAM.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Command
synopsis
winbindd[options]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Options
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
-d
debuglevel
new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
(sometimes
logging) level. The level can range from 0 to 10. Specifying the
sharedSets
filesthe
anddebug
printers
from Unixcalled
clients.
value on the command line overrides the value specified in the smb.conf file. Debug level 0 logs
only the most important messages; level 1 is normal; levels 3 and above are primarily for
debugging.
-i
Runswinbindd interactively. This option is used to override the default, which is for winbindd to
detach and run as a daemon.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
findsmb
This Perl script reports information about systems on the subnet that respond to SMB name-query
requests. The report includes the IP address, NetBIOS name, workgroup/domain, and operating system
of each system.
Table of Contents
Index
Reviews
Command
synopsis
Reader
Reviews
Errata
Using Samba,
findsmb
[subnet_broadcast_address]
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
If a different subnet's broadcast address is provided, it will find SMB servers on that subnet. If no subnet
broadcast address is supplied, findsmb will look on the local subnet.
Publisher: O'Reilly
Date: from
February
2003
ThePub
output
findsmb
looks like this:
ISBN: 0-596-00256-4
$findsmb
Pages: 556
Slots: 1
*=DMB
+=LMB
Using
Samba, Second
Edition
is a comprehensive
guide to Samba administration. This new edition covers
IP ADDR
NETBIOS
NAME
WORKGROUP/OS/VERSION
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the
SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
--------------------------------------------------------------------Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication*[METRAN]
and filesystem
security
on the
host Unix system, and accessing
172.16.1.1
TOLTEC
[Unix]
[Samba
2.2.6]
shared files and printers from Unix clients.
172.16.1.3
MIXTEC
172.16.1.4
ZAPOTEC
172.16.1.5
HUASTEC
METRAN
172.16.1.6
MAYA
METRAN
172.16.1.7
OLMEC
172.16.1.10
UTE
172.16.1.13
DINE
METRAN
The system with an asterisk (*) in front of its workgroup name is the domain master browser for the
workgroup/domain, and the system with a plus sign (+) preceding its workgroup name is the local
master browser.
Thefindsmb command was introduced during the development of Samba 2.2 and is installed by default
in Samba Versions 2.2.5 and later.
make_smbcodepage
This program is part of the internationalization features of Samba 2.2 and is obsolete in Samba 3.0,
which supports Unicode automatically. The make_smbcodepage program compiles a binary codepage file
from a text-format
codepage
Table of
Contents definition. It can also perform the reverse operation, decompiling a binary
codepage file Index
into a text version. Examples of text-format codepage files can be found in the Samba
distribution
in Reviews
the source/codepages directory. After Samba has been installed, examples of binary
codepages
can
be found
in the directory /usr/local/samba/lib/codepages .
Reader
Reviews
Errata
Command
synopsis
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
make_smbcodepagec|d codepage_number input_file output_file
Publisher: O'Reilly
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
make_unicodemap
This program is part of the internationalization features of Samba 2.2 and is obsolete in Samba 3.0,
which supports Unicode automatically. The make_unicodemap command compiles binary Unicode maps
from text files,Table
so Samba
can display non-ASCII characters in file and directory names via the Unicode
of Contents
international alphabets.
Examples of input mapping files can be found in the directory source/codepages
Index
in
source distribution.
the Samba Reviews
Reader Reviews
Errata
Command
synopsis
Using Samba, 2nd
Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
net
Thenet command, new to Samba 3.0, is a program with a syntax similar to the MS-DOS/Windows
command of the same name. It is used for performing various administrative functions related to
Windows networking,
which can be executed either locally or on a remote system.
Table of Contents
Index
Reviews
Command
synopsis
Reader
Reviews
Errata
Using
net
[method]
Samba, 2nd
function
Edition
[misc_options] [target_options]
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Depending on the function, the method argument can be optional, required, or disallowed. It specifies one
of three methods for performing the operation specified by the rest of the command. It can be ads
(Active Directory), rpc (Microsoft's DCE/RPC), or rap (Microsoft's original SMB remote procedure call). To
determine which methods (if any) can be used with a function, the net help ads,net help rap, and
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
net help rpc commands can be used to list the functions for each method.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Miscellaneous
options
Windows NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
-dlevel
--debug=level
Sets the debug (sometimes called logging) level. The level can range from 0 to 10.
-l
--long
Specifies the long listing mode. This is provided for functions that print informational listings.
-nname
--myname=name
Specifies the NetBIOS name for the client.
-pport
--port=port
Specifies the port number to use.
-sfilename
--conf=filename
Specifies the name of the Samba configuration file, overriding the compiled-in default.
-Uusername[%password]
--user=username[%password]
Specifies the username and, optionally, the password to use for functions that require
authentication.
-Wname
--myworkgroup =name
Specifies the name of the client's workgroup, overriding the definition of the workgroup parameter
in the Samba configuration file.
Target options
-Shostname
Specifies the remote system using a hostname or NetBIOS name.
-Iip_address
Specifies the remote system using its IP address.
Table of Contents
-wworkgroup
Index
Reviews
Specifies
the name of the target domain or workgroup.
Reader Reviews
Errata
Functions
abortshutdown
Publisher: O'Reilly
rpcabortshutdown
function.
PubSee
Date:the
February
2003
adsinfo
ISBN: 0-596-00256-4
Pages: 556
Prints information about the Active Directory server. The method (ads) must be specified to
Slots: 1
differentiate
this function from the rpc info function.
adsjoinOU
Joins the local system to the Active Directory realm (organizational unit) specified by OU. The
must
be specified
to differentiate
this
from the rpc join
Using method
Samba, (ads)
Second
Edition
is a comprehensive
guide
to function
Samba administration.
This function.
new edition covers
ads
leave of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
all versions
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Removes
theaslocal
systemdomain
from the
Active Directory
realm.
Samba's
new role
a primary
controller
and domain
member server, its support for the use of
ads
password
username@
REALM
-U
admin_username@
REALM%admin_
password
Windows NT/2000/XP authentication and filesystem security on the
host Unix system, and accessing
shared files and printers from Unix clients.
Changes the Active Directory password for the user specified by username@REALM. The
administrative account authentication information is specified with the -U option. The Active
Directory realm must be supplied in all uppercase.
ads printer info[printer] [server]
Prints information on the specified printer on the specified server. The printer argument defaults
to an asterisk (*), meaning all printers, and the server argument defaults to localhost.
ads printer publishprinter_name
Publishes the specified printer in Active Directory.
ads printer removeprinter_name
Removes the specified printer from Active Directory.
ads searchexpr attrib
Performs a raw Active Directory search, using the standard LDAP search expression and attributes
specified by the expr and attrib arguments, respectively.
ads status
Prints details about the Active Directory computer account of the system.
change localhost pass
Changes the Active Directory password for the local system's computer trust account.
domain
Lists the domains or workgroups on the network.
file
Lists open files on the server.
file closefile_id
Table
of Contents
Adds the
specified
group. This function accepts the miscellaneous option -Ccomment (which can
also be Index
specified as - -comment=string) to set the descriptive comment for the group.
group deleteReviews
group_name
Reader Reviews
Deletes Errata
the specified group.
groupmember
add
group_name username
Using
Samba, 2nd
Edition
Lists
users who are members of the specified group.
Slots: the
1
help
Prints a help message for the net command.
helpmethod
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
Samba
from 2.0
2.2, including
selected
features
from This
an alpha
version
of 3.0,
as can
well as
Prints of
a help
message
forto
method,
which can
be ads,
rap, or rpc.
lists the
functions
that
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
use the method, along with a brief description.
Samba's new role as a primary domain controller and domain member server, its support for the use of
helpfunction
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
sharedPrints
files and
printers
fromfor
Unix
a help
message
theclients.
specified function, which can be more than one word.
info
Must be preceded by a method. See the adsinfo and rpcinfo functions.
join
Joins the computer to a Windows NT domain or Active Directory realm. If the method argument is
not specified, a check is made to determine if Active Directory is in use, and if so, ads join is
performed. Otherwise, rpc join is run. See also the ads join and rpc join functions.
leave
Must be preceded by a method. See the adsleave function.
lookup dc[domain]
Prints the IP address of the specified domain's domain controllers. The domain defaults to the value
of the workgroup parameter in the Samba configuration file.
lookup hosthostname [type]
Prints the IP address of the specified host.
lookup kdc[realm]
Prints the IP address of the specified realm's Kerberos domain controller. If realm is not specified,
it defaults to the value of the realm parameter in the Samba configuration file.
lookup ldap[domain]
Prints the IP address of the specified domain's LDAP server. If domain is not specified, it defaults to
the value of the workgroup parameter in the Samba configuration file.
lookup master[domain]
Prints the IP address of the master browser of the specified domain or workgroup. If domain is not
specified, it defaults to the value of the workgroup parameter in the Samba configuration file.
Table of Contents
Reviews
Reader Reviews
ByDavidPrints
Collier-Brown
, Robert(including
Eckstein, Jaythe
Ts
information
printq deletequeue_name
Publisher: O'Reilly
the specified
PubDeletes
Date: February
2003
Slots: 1
Aborts
the shutdown of a remote server.
rpc info
Prints information about the server's domain. The method (rpc) must be specified to differentiate
function
from
the ads
function.
Using this
Samba,
Second
Edition
is info
a comprehensive
guide to Samba administration. This new edition covers
rpc
join of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
all versions
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Joins
a computer
to a Windows
NTcontroller
domain. and
If the
-Uusername%password
option
is included,
the of
Samba's
new
role as a primary
domain
domain
member server, its
support
for the use
specified
username
and
password
will
be
used
as
the
administrative
account
required
for
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
withfrom
the PDC.
the -U option is not included, this function can be used only to join
sharedauthenticating
files and printers
Unix If
clients.
the computer to the domain after the computer account has been created using the Server
Manager. The method (rpc) must be specified to differentiate this function from the adsjoin
function.
rpc shutdown
Shuts down a server. This function accepts the -r,-f,-t, and -c miscellaneous options. The -r
option (which can also be specified as --reboot) requests that the system reboot after shutting
down. The -f option (which can also be specified as --force) forces a shutdown. The -ttimeout
option (which can also be specified as - -timeout=number) specifies the number of seconds to wait
before shutting down, and the -ccomment option (which can also be specified as - comment=string) can be used to specify a message to the client user. On Windows, the comment
appears in the Message area in the System Shutdown dialog box.
rpc trustdom adddomain_name
Adds an account for the trust relationship with the specified Windows NT domain.
rpc trustdom establishdomain_name
Establishes a trust relationship with the specified Windows NT domain.
rpc trustdom revokedomain_name
Revokes the trust relationship with the specified Windows NT domain.
search
See the ads search function.
server
Lists servers in the domain or workgroup, which defaults to the value of the workgroup parameter
in the Samba configuration file.
session
Lists clients with open sessions to the server.
Index
Reviews
Adds a share
the target server. The name of the share and the folder to be shared are specified
Reader on
Reviews
by
the
share_name=server_path
argument, with server_path the Windows directory name, with
Errata
spaces
and
other
special
characters
(if any) quoted and with the backslashes escaped (e.g.,
Using Samba, 2nd Edition
"data=C:\\DocumentsandSettings\\jay\\Desktop\\data"). The -Ccomment option (which can
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
also be specified as - -comment=string) can be used to define a description for the share. The -M
number option (which can also be specified as --maxusers=number) can be used to set the
Publisher:
O'Reillynumber of users that can connect to the share. The method (rap or rpc) might need to
maximum
Pubbe
Date:
February for
2003
specified
this function to work. The regular folder icon cannot change into a "shared folder"
ISBN:in
0-596-00256-4
icon
Windows Explorer until the display is refreshed.
sharePages:
delete
556share_name
Slots: 1
Deletes a share from the target server. The share_name argument is simply the name of the share
on the target server, not a UNC. The method (rap or rpc) might need to be specified for this
function to work. The "shared folder" icon in Windows Explorer cannot change back to the regular
folder icon until the display is refreshed.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
shutdown
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
tool. Updated for Windows 2000, ME, and XP, the book also explores
See the
rpc shutdown
function.
Samba's
new
role
as
a
primary
domain
controller and domain member server, its support for the use of
status
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
sharedSee
filesthe
and
printers
from
Unix clients.
ads
status
function.
time
Displays the system timein Unix date command formaton the target system.
time set
Sets the local system's hardware clock using the time obtained from the operating system.
time system
Sets the time on the local system using the time obtained from the remote system.
time zone
Prints the time zone (in hours from GMT) in use on the system.
trustdom add
See the rpc trustdom add function.
trustdom establish
See the rpc trustdom establish function.
trustdom revoke
See the rpc trustdom revoke function.
user
Lists user accounts. The method can be specified as ads,rap, or rpc.
user addusername [password]
Adds a user account for the user specified by username. The -ccomment option (which can also be
specified as - -comment=string) can be used to set a comment for the account. The -F
user_flags option can be used to set flags (specified in numeric format) for the account. The
method can be specified as ads,rap, or rpc.
user deleteusername
Deletes the specified user's account. The method can be specified as ads,rap, or rpc.
user infousername
Lists the domain groups to which the specified user belongs. The method can be specified as ads,
rap, or rpc.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
nmblookup
Thenmblookup program is a client program that allows command-line access to NetBIOS name service
for resolving NetBIOS computer names into IP addresses. The program works by broadcasting its queries
on the local subnet
a machine with the specified name responds. You can think of it as a Windows
Table ofuntil
Contents
analog of nslookup
Index or dig. This is useful for looking up regular computer names, as well as specialpurpose
names,
such as _ _MSBROWSE_ _ . If you wish to query for a particular type of NetBIOS name,
Reviews
add
the
NetBIOS
type
to the end of the name, using the format netbios_name#<dd>.
Reader
Reviews
Errata
Command
synopsis
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
nmblookup[options] netbios_name
Publisher: O'Reilly
Options
ISBN: 0-596-00256-4
-A
Pages: 556
Slots: 1
TOLTEC
<00> -
M <ACTIVE>
TOLTEC
<03> -
M <ACTIVE>
TOLTEC
<20> -
M <ACTIVE>
..__MSBROWSE__.
<01> - <GROUP> M <ACTIVE>
Table of Contents
Index
METRAN
METRAN
Reviews
Reader Reviews
Errata
METRAN
<1b> -
M <ACTIVE>
METRAN
<1d> -
M <ACTIVE>
Publisher: O'Reilly
METRAN
Pub
Date: February 2003
Specifies the location of the Samba configuration file. Although the file defaults to
Slots: 1
/usr/local/samba/lib/smb.conf , you can override it here on the command line. Normally used for
debugging.
-T
Using Translates
Samba, Second
Edition is
a comprehensive
guide to Samba administration. This new edition covers
IP addresses
into
resolved names.
all unicast_address
versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
-U
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
Performs
new role
a unicast
as a primary
query domain
to the specified
controller
address.
and domain
Used member
with -R to
server,
query its
WINS
support
servers.
for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Note
that
nmblookup
hasfrom
no option
for setting the workgroup. You can get around this by putting
shared
files
and printers
Unix clients.
workgroup=workgroup_name in a file and passing it to nmblookup with the -s option.
pdbedit
This program, new to Samba 3.0, can be used to manage accounts that are held in a SAM database. The
implementation of the database can be any of the types supported by Samba, including the smbpasswd
file, LDAP, NIS+
and
the tdb database library. The user must be the superuser to use this tool.
Table
of Contents
Index
Reviews
Command
synopsis
Reader
Reviews
Errata
Using Samba,
pdbedit
[options]
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Options
Publisher: O'Reilly
-a
Adds the user specified by the -u option to the SAM database. The command issues a prompt for
the user's password.
Slots: 1
-ddrive_letter
Pages: 556
Sets the Windows drive letter to which to map the user's home directory. The drive letter should be
specified as a letter followed by a colone.g., H:.
Using
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
-D
debug_level
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
Setsgraphical
the debugconfiguration
(sometimes tool.
calledUpdated
logging)for
level.
Windows
The level
2000,
can
ME,
range
and from
XP, the
0 tobook
10. Debug
also explores
level 0
Samba's
logsnew
only
role
theas
most
a primary
important
domain
messages.
controller
Level
and1 domain
is normal,
member
and levels
server,
3 and
its support
above are
forprimarily
the use of
for
Windows
debugging.
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
-e
pwdb_backend
files and printers from Unix clients.
Exports the user account database to another format, written to the specified location. Used for
migrating from one type of account database to another. The pwdb_backend argument is specified
in the format of a database type, followed by a colon, then the location of the database. For
example, to export the existing account database to an smbpasswd database in the file
/usr/local/samba/private/smbpw ,pwdb_backend would be specified as
smbpasswd:/usr/local/samba/private/smbpw. The allowable database types are smbpasswd,
smbpasswd nua,tdbsam,tdbsam nua,ldapsam,ldapsam_nua, and plugin.
-ffull_name
Sets the full name of the user specified with the -u option.
-hunc
Sets the home directory path (as a UNC) for the user specified with the -u option.
-ipwdb_backend
Specifies a password database backend from which to retrieve account information, overriding the
one specified by the passdb backend parameter in the Samba configuration file. This, along with
the-e option, is useful for migrating user accounts from one type of account database to another.
See the -e option regarding how to specify the pwdb_backend argument.
-l
Lists the user accounts in the database. See also the -v option.
-m
Indicates that the account is a computer account rather than a user account. Used only with the -a
option when creating the account. In this case, the -u option specifies the computer name rather
than a username.
-punc
Sets the directory in which the user's profile is kept. The directory is specified as a UNC.
-sunc
Specifies the UNC of the user's logon script.
-uusername
Specifies the username of the account to add (with the -a option), delete (with the -x option), or
modify.
-v
Selects Table
verbose
mode when listing accounts with the -l option. The account fields will be printed.
of Contents
-w
-x
Index
Reviews
Selects Reader
the smbpasswd
listing mode, for use with the -l option, which prints information in the
Reviews
same format
as
it
would
appear in an smbpasswd file.
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
rpcclient
This is a program for issuing administrative commands that are implemented using Microsoft RPCs. It
provides access to the RPCs that Windows administrative GUIs use for system management. The
rpcclient command
mainly for use by advanced users who understand the RPCs. More information on
Table ofisContents
these can be found
Index in Microsoft's Platform Software Development Kit (SDK), available for download from
the
Microsoft web
site at http://www.microsoft.com.
Reviews
Reader Reviews
You can run a single rpcclient command by using the -c command string option, or interactively with
Errata
rpcclient prompting for commands.
Using Samba, 2nd Edition
Command Synopsis
Publisher: O'Reilly
Pub Date:
February
2003
rpcclient
server
[options]
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Options
-Afilename
a file from
which
read the authentication
values administration.
used in the connection.
format
of
Using Specifies
Samba, Second
Edition
is atocomprehensive
guide to Samba
This newThe
edition
covers
the file
as follows:
all versions
ofisSamba
from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
username
= value configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
the SWAT graphical
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP
password
= value
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
domain
= value
This option is used to avoid password prompts or to have the password appear in plain text inside scripts.
The permissions on the file should be very restrictive (0600, for example) to prevent access from
unwanted users.
-ccommand_string
Executes a sequence of semicolon-separated commands. Commands are listed in the following
section.
-ddebuglevel
Sets the debug (sometimes called logging) level. The level can range from 0 to 10. Specifying the
value on the command line overrides the value specified in the smb.conf file. Debug level 0 logs
only the most important messages; level 1 is normal; levels 3 and above are primarily for
debugging and slow the program considerably.
-h
Prints a summary of options.
-llogbasename
Sets the filename for log/debug files. The extension .client is appended to the filename.
-N
Does not prompt for a password. This is used when Samba is configured for share-mode security
and a service with no password is being accessed.
-sfilename
Specifies the location of the Samba configuration file, which by default is usually
/usr/local/samba/lib/smb.conf .
-Uusername[%password]
Sets the SMB username or username and password to use. Be careful when specifying the
password with %password; this is a major security risk. If %password is not specified, the user will
be prompted for the password, which will not be echoed. Normally the user is set from the USER or
LOGNAME environment variable. The -U option by itself means to use the guest account. See also A.
-Wdomain
Sets the domain, overriding the workgroup parameter in the Samba configuration file. If the
domain Table
is theofserver's
Contents NetBIOS name, it causes the client to log on using the server's local SAM
database
rather
than the SAM of the domain.
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
rpcclient commands
Aside from a few miscellaneous commands, the rpclient commands fall into three groups: LSARPC,
SAMR, and SPOOLSS. The function names mentioned in some of the commands are those documented in
the Microsoft Platform
SDK.
Table of Contents
Index
Reviews
General
commands
Reader Reviews
Errata
Using Samba,level
debuglevel
2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Sets the debugging level to level. With no argument, the current debugging level is printed.
help
Publisher: O'Reilly
PubPrints
Date: February
help on2003
the
quit
commands.
ISBN: 0-596-00256-4
Pages: 556
Exits
rpcclient. A synonym is exit.
Slots: 1
Lists alias groups in the domain, along with their group RIDs. The type argument can be either
builtin, to list Windows built-in groups such as Administrators and PowerUsers, or domain, to
list groups in the domain. See also the queryuseraliases command.
enumdomgroups
Lists the groups in the domain, along with their group RIDs.
queryaliasmemuser_rid
Prints information regarding alias membership. See also the queryuseraliases command.
Table of Contents
querydispinfo
Index
Prints out
the account database. The information printed includes the RID, username, and full
Reviews
name ofReader
each user.
The RID is printed in hexadecimal notation and can be used in this form for
Reviews
commands
that take a RID as an argument.
Errata
querydominfo
Using Samba, 2nd Edition
ByDavidPrints
Collier-Brown
, Robertregarding
Eckstein, Jay
Ts domain.
information
the
Given
a group RID, prints the group name, description, number of members, and group
ISBN: 0-596-00256-4
description.
Pages: 556
queryuseruser_rid
Slots: 1
Given a user RID, prints the corresponding username, full name, and other information pertaining
to the user.
queryuseraliasestype user_rid
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
Samba
2.0 toThe
2.2,type
including
selected
features
an alpha
version
of 3.0,are
as used
well as
Prints of
aliases
forfrom
the user.
argument
can be
either from
builtin
or domain.
Aliases
the SWAT
configuration
tool.
Updated
for like
Windows
2000, ME,
and XP,
alsoto
explores
with graphical
the Windows
messaging
service
and act
usernames,
but they
canthe
be book
attached
a
Samba's
new role
as a than
primary
domain
and domain
member
the use ofon
computer
rather
a user.
Thiscontroller
allows messages
intended
for aserver,
user toits
besupport
sent tofor
a computer
Windows
NT/2000/XP
and on,
filesystem
security
on the
host Unix
system, and accessing
which
the user isauthentication
either not logged
or logged
on under
another
username.
shared files and printers
from Unix clients.
queryusergroups
user_rid
Prints information on each group inhabited by the user.
querygroupmemgroup_rid
Prints the RID and attributes for each member of the group.
samlookupnamestype username
Looks up the username in the SAM database and prints its associated RID. The type argument can
be either builtin, to look up built-in Windows usernames, or domain, to look up names in the
domain.
samlookupridstype rid
Looks up rid in the SAM database and prints its associated group or username. The type argument
can be either builtin, to look up built-in Windows usernames, or domain, to look up names in the
domain. The RID argument can be given in either 0xDDD hexadecimal notation or decimal.
samquerysecobj
Prints information on security objects (such as ACLs) in the SAM database.
Table of Contents
NULL:\
Index
Reviews
Default
DataReader
Type:\
Reviews
Errata
followed
by a2nd
comma-separated
list of files. Any empty fields should contain the string NULL.
Using Samba,
Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
on the remote server as sharename. The printer driver must already be installed on
and the port must be a valid port name returned by enumports.
deldriver
ISBN:drivername
0-596-00256-4
Pubthe
Date:
February
2003
server
with
adddriver,
Pages: 556
Deletes
a printer driver (for all architectures) from the server's list of printer drivers.
Slots: 1
enumports[level]
Prints information regarding the printer ports on the server. The level argument can be 1 or 2.
Level 1 is the default and prints out only the Port Name. Information level 2 is the Port Name,
Using Monitor
Samba, Name,
SecondDescription,
Edition is a comprehensive
and Port Type. guide to Samba administration. This new edition covers
all
versions
of
Samba
from
2.0
to
2.2, including selected features from an alpha version of 3.0, as well as
enumdrivers[level]
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new
as a primary
andlevel
domain
memberspecifies
server, its
for the
use of
Lists
all role
the printer
driversdomain
on the controller
system. The
argument
thesupport
information
level.
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
Level 1 is the default and prints the Driver Name(s). Level 2 prints the Version, Driver Name,
sharedArchitecture,
files and printers
Unix
clients.
Driverfrom
Path,
Data
File, and Config File. Level 3 prints the contents of Level 2, plus the
Help File, one or more Dependent Files, Monitor Name, and Default Data Type.
enumprinters[level]
Lists all installed printers, regardless of whether they are shared. The level argument specifies the
information level. Level 1 is the default, and prints Flags, Name, Description, and Comment. Level
2 prints the Server Name, Printer Name, Share Name, Port Name, Driver Name, Comment,
Location, Separator File, Print Processor, Data Type, Parameters, Attributes, Priority, Default
Priority, Start Time, Until Time, Status, Current Jobs, Average PPM (pages per minute), and a
Security Descriptor.
getdriver[level] printername
Prints the printer driver information for the given printer. The level argument specifies the
information level.
Level 1 is the default, and prints the Driver Name. Level 2 prints the Version, Driver Name,
Architecture, Driver Path, Data File, and Config File. Level 3 prints the contents of level 2, plus the
Help File, one or more Dependent Files, Monitor Name, and Default Data Type.
getdriverdirarch
Retrieves the share name and directory for storing printer driver files for a given architecture.
Possible values for arch are "Windows4.0" for Windows 95/98/Me, "WindowsNTx86" for Windows
NT on Intel, "WindowsNTPowerPC" for Windows NT on PowerPC, "WindowsAlphaAXP" for Windows
NT on Alpha, and "WindowsNTR4000" for Windows NT on MIPS. Include the quote marks in the
command.
getprinterprintername
Prints the current printer information. The level argument specifies the information level.
openprinterprintername
Attempts to open and close a specified printer and reports whether it was successful.
setdriverprintername drivername
Unconditionally updates the printer driver used by an installed printer. Both the printer and printer
driver must already be correctly installed on the print server.
setprinterprintername comment
Assigns a comment string to a printer.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
smbcacls
This program provides a way of modifying Windows NT ACLs on files and directories shared by the Samba
server.
Table of Contents
Index
Command
synopsis
Reviews
Reader Reviews
smbcacls
//server/share
Errata
filename[options]
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Options
-Aacls
Publisher: O'Reilly
Pub Date: February 2003
Adds
one or more ACLs to the file or directory. Any ACLs already existing for the file or directory
ISBN: 0-596-00256-4
are unchanged.
Pages: 556
-Macls
Slots: 1
Modifies the mask of the ACLs specified. Refer to the following section, "Specifying ACLs," for
details.
-Dacls
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of the
Samba
from ACLs.
2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Deletes
specified
theacls
SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
-S
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
authentication
and
filesystem
securityset
on on
thethe
host
system, and
SetsNT/2000/XP
the specified
ACLs, deleting
any
ACLs previously
fileUnix
or directory.
Theaccessing
ACLs must
sharedcontain
files and
from Unix
clients.
at printers
least a revision,
type,
owner, and group.
-Uusername
Sets the username used to connect to the specified service. The user is prompted for a password
unless the argument is specified as username%password. (Specifying the password on the
command line is a security risk.) If -Udomain\\username is specified, the specified domain or
workgroup will be used in place of the one specified in the smb.conf file.
-Cusername
Changes the owner of the file or directory. This is a shortcut for -MOWNER:username. The username
argument can be given as a username or a SID in the form S-1-N-N-D-D-D-R.
-Ggroupname
Changes the group of the file or directory. This is a shortcut for -MGROUP:groupname. The
groupname argument can be given as a group name or a SID in the form S-1-N-N-D-D-D-R.
-n
Causes all ACL information to be displayed in numeric format rather than in readable strings.
-h
Prints a help message.
Specifying ACLs
In the previous options, the same format is always used when specifying ACLs. An ACL is made up of one
or more Access Control Entries (ACEs), separated by either commas or escaped newlines. An ACE can be
one of the following:
REVISION:revision_number
OWNER:username_or_SID
GROUP:group_name_or_SID
ACL:name_or_SID:type/flags/mask
Therevision_number should always be 1. The OWNER and GROUP entries can be used to set the owner and
group for the file or directory. The names can be the textual ones or SIDs in the form S-1-N-N-D-D-D-R.
TheACL entry specifies what access rights to apply to the file or directory. The name_or_SID field
specifies to which user or group the permissions apply and can be supplied either as a textual name or a
SID. An ACE can be used to either allow or deny access. The type field is set to 1 to specify a permission
of Contents
to be allowed Table
or 0 for
specifying a permission to deny. The mask field is the name of the permission and is
Index
one of the following:
Reviews
Reader Reviews
Errata
Read access.
Using Samba,
2nd Edition
W
Write access.
X
Publisher: O'Reilly
Pub Date: February 2003
Execute
permission.
ISBN: 0-596-00256-4
D
Pages: 556
Slots: 1
Permission to delete.
P
Change permissions on the object.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
O
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
Takegraphical
ownership.
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
The
following
combined
permissions can
be specified:
Windows
NT/2000/XP
authentication
and also
filesystem
security on the host Unix system, and accessing
shared files and printers from Unix clients.
READ
Equivalent to RX permissions
CHANGE
Equivalent to RWXD permissions
FULL
Equivalent to RWXDPO permissions
Theflags field is for specifying how objects in directories are to inherit their default permissions from
their parent directory. For files, flags is normally set to 0. For directories, flags is usually set to either 9
or 2.
smbclient
Thesmbclient program is the "Swiss army knife" of the Samba suite. Initially developed as a testing tool,
it has become a command shell capable of acting as a general-purpose Unix client, with a command set
very similar toTable
thatofofContents
ftp. It offers the following set of functions:
Index
Reviews
Errata
Interactive
printing to shared SMB printers
Interactive
tar,Robert
format
archiving
ByDavid
Collier-Brown
Eckstein
, Jay Ts
Sending messages on the SMB network
Publisher: O'Reilly
Pub
Date: February
2003
Batch
mode tar
format
archiving
ISBN: 0-596-00256-4
"What
services do you have?" querying
Pages: 556
Slots: 1
Debugging
Command
synopsis
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
smbclient
//server/share
[ password]
[options]
the SWAT graphical
configuration
tool. Updated
for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
It is possible to run smbclient noninteractively, for use in scripts, by specifying the -c option along with a
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
list
of commands
to execute.
smbclient runs in interactive mode, prompting for commands
shared
files and printers
fromOtherwise,
Unix clients.
such as this:
smb:\>
The backslash in the prompt is replaced by the current directory within the share as you change your
working directory with smbclient'scd command.
Options
-Aauthfile
Specifies a file from which to read the username and password used for the connection. The format
of the file is as follows:
username = value
password = value
domain
= value
This is to avoid having the password prompted for or have it appear in plain text in scripts. The
permissions on the file should be very restrictive (0600, for example) to prevent access by unwanted
users.
-bbuffer_size
Sets the size of the buffer used when transferring files. It defaults to 65520 bytes and can be
changed as a tuning measure. Generally it should be quite large or set to match the size of the
buffer on the remote system. It can be set smaller to work around Windows bugs: some Windows
98 systems work best with a buffer size of 1200.
-BIP_addr
Index
-D
init_dir Reviews
Reader Reviews
Upon starting up, causes smbclient to change its working directory to init_dir on the remote
Errata
host.
Using Samba, 2nd Edition
-E
Publisher: O'Reilly
Pub Date: February 2003
Slots: the
1
Sets
IP address of the server to which the client connects.
-iscope
Table of Contents
Resets the archive attribute on files after they have been saved. See also the g option.
bsize
Index
Reviews
Reader
Sets
theReviews
block size for writing the tar file, in 512-byte units.
Errata
Backs up
onlyEckstein
files that
ByDavid Collier-Brown
, Robert
, Jay have
Ts
Ifilename
Publisher: O'Reilly
Includes files and directories. This is the default, so specifying this is redundant. To perform
see also the r option.
0-596-00256-4
NISBN:
filename
q
Suppresses diagnostics.
r
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Performs regular expression matching, which can be used along with the I or E option to
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
include or exclude files.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Xfilename
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Excludes files and directories.
-Uusername
Sets the username and, optionally, the password used for authentication when connecting to the
share.
-Wworkgroup
Specifies the workgroup/domain in which smbclient will claim to be a member.
smbclient commands
help[smbclient_command]
With no command specified, prints a list of available commands. If a command is specified as an
argument, a brief help message will be printed for it.
![shell_command]
Shell escape. With no command specified, runs a Unix shell. If a command is specified, runs the
command in a Unix shell.
altnamefilename
Causessmbclient to request from the server and then print the old-style, 8.3-format filename for
the specified file.
cancelprint_jobid [...]
Causessmbclient to request the server to cancel one or more print jobs, as specified by the
numeric job IDs provided as arguments. See also the queue command, which prints job IDs.
chmodfilename octal_mode
Requests that the server change the Unix file permissions on filename to octal_mode, specified in
octal numeric format. Works only if the server supports Unix CIFS extensions.
chownfilename UID GID
Requests that the server change the owner and group of the file specified by filename to those
provided as decimal numeric arguments UID and GID. Works only if the server supports Unix CIFS
extensions.
cd[directory]
With no argument, prints the current working directory on the remote system. If a directory name
Table
Contents
is supplied
asofan
argument, changes the working directory on the remote system to that specified.
Index
delfilename
Reviews
Requests
Reader
that Reviews
the server delete one or more files, as specified by the argument, from the current
workingErrata
directory. The argument can be a filename globbing pattern using the * and ? characters.
dir
Using[filename]
Samba, 2nd Edition
With no arguments, prints a list of files and directories in the working directory on the server. If an
argument is provided, only files and directories whose names match the argument will be listed.
Publisher:
O'Reilly
The argument
can be a filename globbing pattern using the * and ? characters.
Pub Date: February 2003
exit
ISBN: 0-596-00256-4
Quits 556
the
Pages:
argument, from the current working directory on the server to the local system. When recursion is
on, the pattern argument is used to match directories in the current working directory, and the
pattern specified by the mask command is used for matching files within each directory and all
subdirectories. See also the lowercase,mask, and recurse commands.
printfilename
Prints the specified file. This requires that smbclient be connected to a print share. See also the
printmode command.
printmodemode
Table of Contents
Sets theIndex
mode that is used by the print command. The mode can be either text, for printing text
files such
Reviews
as the ASCII files commonly found on Unix, or graphics, for printing binary files.
prompt
Reader Reviews
Errata
Toggles
the
prompting
Using Samba,
2nd
Edition
mode. When prompting is on (the default), the mget and mput commands
will interactively prompt the user for permission to transfer each file. The user can answer either y
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
(yes) or n (no), followed by a newline, to this prompt. When prompting is off, all the files will be
transferred with no prompts issued.
O'Reilly
putPublisher:
local_file
[remote_file]
Pub Date: February 2003
Copies
the file specified by local_file from the local to the remote system. If no remote_file
ISBN: 0-596-00256-4
is specified, smbclient will name the remote file the same as it is named on the local
system.
If
remote_file is specified, it will be used as the name of the remote copy. See also the
Slots: 1
lowercase command.
argument
Pages:
556
queue
Prints information on the print queue on the server. This requires that smbclient is connected to a
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
print share.
all
versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
quit
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role for
as a
primary domain controller and domain member server, its support for the use of
A synonym
exit.
Windows
NT/2000/XP
authentication
and filesystem security on the host Unix system, and accessing
rddirectory
shared files and printers from Unix clients.
A synonym for rmdir.
recurse
Toggles the recursion mode, which affects the mget and mput commands. When recursion is off
(the default), the mget and mput commands will copy only files from the current working directory
that match the file-globbing pattern specified as an argument to the command, and the pattern set
by the mask command is ignored. When recursion is turned on, the mget and mput commands
recursively traverse any directories that match the pattern specified as the argument to the
command, and the pattern set by the mask command is used to match files in those directories.
rmfilename
A synonym for del.
rmdirdirectory
Requests that the server remove the specified directory.
setmodefilename attributes
Requests that the server assign the specified MS-DOS file attributes on the specified file. The
attributes argument has the format of a leading plus sign (+) or minus sign (-) either to set or to
unset the attribute(s), respectively, followed by one or more of the characters r (read), s (system),
h (hidden), or a (archive).
symlinklink_name filename
Requests that the server create a symbolic link named link_name to filename. This command
works only if the server supports Unix CIFS extensions. The server will not create a link that refers
to a file not in the share to which smbclient is connected.
tarcmd_str
Performs an archiving operation using the tar format. This is the interactive form of the -T
command-line operation, and the cmd_str argument is specified in the same manner. See also the
tarmode command.
blocksizesize
Sets the block size, in units of 512 bytes, for files written by the tar command.
tarmodemode ...
Specifies how the tar command performs its archiving, including how it handles the archive
attribute on files. Multiple mode arguments can be provided, chosen from the following:
Table of Contents
full
Index
AllReviews
files will be included, regardless of whether their archive attribute is set. This is the
default.
Reader Reviews
inc
Errata
Only files that have the archive attribute set will be included in the backup.
ByDavidreset
Collier-Brown, Robert Eckstein, Jay Ts
Thearchive
Publisher: O'Reilly
noreset
Pub Date: February
attribute will be unset by tar after the file is included in the archive.
2003
ISBN: 0-596-00256-4
Pages:
556
system
Slots: 1
Files with the system attribute set will be included in the archive. This is the default.
nosystem
Files
with the
system
set will guide
not betoincluded
in the archive. This new edition covers
Using Samba,
Second
Edition
is a attribute
comprehensive
Samba administration.
hidden
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Files with the hidden attribute set will be included in the archive. This is the default.
Samba's new role as a primary domain controller and domain member server, its support for the use of
nohidden
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Files with the hidden attribute set will not be included in the archive.
verbose
As files are included in the archive (when creating the archive) or are read from the archive
(when extracting it), the name of each file will be printed. This is the default.
noverbose
This turns verbose mode off, causing tar to perform its work quietly.
quiet
An antonym for the verbose mode. When quiet is on, verbose is off, and vice versa.
smbcontrol
Table of Contents
Command
Index
synopsis
Reviews
Reader
Reviews
smbcontrol
-i
[options]
Errata
or:
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Options
Pub Date: February 2003
-i
ISBN: 0-596-00256-4
Pages: 556
Slots: smbcontrol
1
Runs
interactively, executing commands until a blank line or "q" is read. The user must
have superuser privileges.
-sfilename
the location
of is
the
Samba configuration
Using Specifies
Samba, Second
Edition
a comprehensive
guide file.
to Samba administration. This new edition covers
-d
all debuglevel
versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Sets
therole
debugging
level for
logging.
The debug
level can
be set from
to its
10.support for the use of
Samba's
new
as a primary
domain
controller
and domain
member
server,
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Whether
smbcontrol
commands
are clients.
issued in interactive mode or from the command line, the commands
shared files
and printers
from Unix
are in the same format. Each command has up to three parts:
process
Specifies the process or group of processes to which to send the message. If process is smbd, all
smbd processes will receive the message. If process is nmbd, only the main nmbd process
(identified by Samba's nmbd.pid file) receives the message. If process is the numeric PID of a
running process on the system, that process will receive the message.
message-type
Specifies the type of message that is sent. For more information, see smbcontrol message types
that follows.
parameters
Specifies additional parameters required by some messages.
Table of Contents
ControlsIndex
profiling statistics collection. If mode is on, profile statistics will be collected. If mode is off,
collection
of statistics is turned off. If mode is specified as count, only counting statistics are
Reviews
collectedReader
(and Reviews
not timing statistics). If mode is flush, the data set is cleared (initialized).
profilelevelErrata
Publisher:
SendsO'Reilly
a printer
notify message to Windows NT/2000/XP for the specified printer. This message can
Warning: no message is printed if the printer_name parameter is specified
Pubbe
Date:
February
sent
only 2003
to smbd.
incorrectly.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
smbgroupedit
This command, new to Samba 3.0, sets up mappings between Unix groups and Windows NT/2000/XP
groups and also allows a Unix group to become a domain group. This command must be run by the
superuser.
Table of Contents
Index
Reviews
Command
synopsis
Reader
Reviews
Errata
Options
Publisher: O'Reilly
-aUnix_group_name
Pub Date: February 2003
ISBN: 0-596-00256-4
Adds a mapping for the specified Unix group. The -n option is used along with this option to specify
the Windows NT group to which the Unix group is mapped.
Pages: 556
-cSID
Slots: 1
Changes a mapping between a Windows NT group and a Unix group. The Windows NT group is
specified as a SID with this option, and the Unix group is specified with the -u option.
Using
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
-d
description
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
Updated
for will
Windows
2000,
ME, with
and it.
XP, the book also explores
Specifies
a comment
for thetool.
mapping,
which
be stored
along
Samba's new role as a primary domain controller and domain member server, its support for the use of
-l
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
usedprinters
with the
-v option,
prints a long listing. This is the default. The information printed
sharedWhen
files and
from
Unix clients.
includes the name of the Windows NT group, its SID, its corresponding Unix group (if a mapping
has been defined), the group type, the comment, and the privileges of the group.
-nWindows_group_name
Specifies the name of the Windows NT group. Used with the -a option.
-pprivilege
Used along with the -a option to specify a Windows NT privilege to be given to the Unix group.
-s
When used with the -v option, prints a short listing. The information printed includes just the name
of the Windows NT group, its SID, and, if a mapping has been defined, its corresponding Unix
group. This option is useful for determining the SID of a group, for use with the -c option.
-tTYPE
Assigns a Windows group type to the group. TYPE is a single character, and is one of b (built-in), d
(domain), or l (local).
-uUnix_group_name
Specifies the name of the Unix group to map to the Windows NT group. Used with the -c option.
-v
Prints a list of groups in the Windows NT domain in which the Samba server is operating. See also
the-l and -s options.
-xUnix_group_name
Deletes the mapping for the Unix group specified.
smbmnt
This is a low-level helper program for mounting smbfs filesystems. It used by smbmount to do the
privileged part of the mount operation on behalf of an ordinary user. Generally, users should not run this
command directly.
Table of Contents
Index
Reviews
Command
synopsis
Reader
Reviews
Errata
Using Samba,
smbmnt
mnt_point
2nd Edition
[options]
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Options
Publisher: O'Reilly
-r
-uuid
Pages: 556
Slots: 1
smbmount
This program mounts an smbfs filesystem on a mount point in the Unix filesystem. It is typically called as
mount.smb from mount, although it can also be run directly by users. After mounting the smbfs
filesystem,smbmount
continues to run as a daemon as long as the filesystem is mounted. It logs events
Table of Contents
in the file log.smbmount
in the same directory as the other Samba log files (which is commonly
Index
/usr/local/samba/var
Reviews by default). The logging level is controlled by the debug level parameter in the
Samba
configuration
file.
Reader Reviews
Errata
Command
synopsis
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
smbmountservice mount_point [-o options]
Publisher: O'Reilly
Date: February
2003specifies the SMB share to mount, given as a UNC. The mount_point argument
ThePub
service
argument
ISBN:
0-596-00256-4
specifies a directory to use as the mount point. The options to smbmount are specified as a commaPages:list
556of key=value pairs. The documented options are as follows. Others can be passed if the
separated
kernel Slots:
supports
1
them.
Options
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versionsname
of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
username=
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role
a primarytodomain
domain
member
its support
for USER
the use
Specifies
theas
username
connectcontroller
as. If thisand
is not
provided,
the server,
environment
variable
willofbe
Windows
NT/2000/XP
and
security onuser/workgroup,
the host Unix system,
and accessing
tried.
The name authentication
can be specified
asfilesystem
username%password,
or
shareduser/workgroup%password.
files and printers from Unix clients.
password=string
Specifies the SMB password. If no password is provided using this option, the username option, or
thecredentials option, the environment variable PASSWD is used. If that also does not exist,
smbmount will prompt interactively for a password.
credentials=filename
Specifies a file that contains a username and password in the following format:
username = value
password = value
uid=number
Sets the Unix user ID to be used as the owner of all files in the mounted filesystem. It can be
specified as a username or numeric UID. Defaults to the UID of the user running smbmount.
gid=number
Sets the Unix group ID to be used as the group for all files in the mounted filesystem. It can be
specified as a group name or a numeric GID. Defaults to the GID of the user running smbmount.
port=number
Sets the TCP port number. This is 139, which is required by most Windows versions.
fmask=octal_mask
Sets the Unix permissions of all files in the mounted filesystem. Defaults to the user's current
umask.
dmask=octal_mask
Sets the Unix permissions of all directories in the mounted filesystem. Defaults to the current
umask.
debug=number
Sets the debugging level.
ip=host
Sets the destination hostname or IP address.
netbiosname=name
Sets the computer name to connect as. This defaults to the hostname of the local system.
Table of Contents
workgroup=name
Index
Sets theReviews
workgroup or domain.
sockopt=optsReader Reviews
Errata
Sets TCP
Using Samba,
2ndsocket
Edition
options.
scope=num
ro
Don't
expect or prompt for a password.
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Mounts
the share read-only.
rw
Mounts the share read-write.
iocharset=
charset
Using
Samba,
Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Setsgraphical
the charset
used by thetool.
Linux
machine
codepage-to-charset
See
also
the
the SWAT
configuration
Updated
forfor
Windows
2000, ME, andtranslation.
XP, the book
also
explores
codepage
option.
Samba's new role as a primary domain controller and domain member server, its support for the use of
codepage=
page
Windows NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Sets the DOS code page. See also the iocharset option.
ttl=milliseconds
Sets the time to live, in milliseconds, for entries in the directory cache. A higher value gives better
performance on large directories and/or slower connections. The default is 1000ms. Try 10000ms
(10 seconds) as a starting value if directory operations are visibly slow.
smbpasswd
Thesmbpasswd program provides the general function of managing encrypted passwords. How it works
depends on whether it is run by the superuser or an ordinary user.
Table of Contents
Reader Reviews
For
the superuser,
Index smbpasswd can be used to maintain Samba's smbpasswd file. It can add or delete
users,
change
their passwords, and modify other attributes pertaining to the user that are held in the
Reviews
smbpasswd file.
Errata
When run by ordinary
users, smbpasswd can be used only to change their encrypted passwords. In this
Using Samba, 2nd Edition
mode of operation, smbpasswd acts as a client to the smbd daemon. The program will fail if smbd is not
operating,
By
David Collier-Brown
if the hosts
, Robert
allow
Eckstein
or ,hosts
Jay Ts deny parameters in the Samba configuration file do not permit
connections from localhost (IP address 127.0.0.1), or if the encrypted passwords option is set to no. It
is also
possible
for smbpasswd to change a user's password when it is maintained on a remote system,
Publisher:
O'Reilly
including
a
Windows
NT domain controller.
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Command
synopsis
Slots: 1
When run by the superuser:
smbpasswd[options] [username] [password]
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
Samba
from of
2.0the
to user
2.2, including
selected features
alpha version
of 3.0,
In this
case,ofthe
username
whose smbpasswd
entry is from
to bean
modified
is provided
as as
thewell as
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
second argument.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
Otherwise:
shared files and printers from Unix clients.
smbpasswd[options] [password]
Superuser-only options
-ausername
Adds a user to the encrypted password file. The user must already exist in the system password file
(/etc/passwd ). If the user already exists in the smbpasswd file, the -a option changes the existing
password.
-dusername
Disables a user in the encrypted password file. The user's entry in the file will remain, but will be
marked with a flag disabling the user from authenticating.
-eusername
Enables a disabled user in the encrypted password file. This overrides the effect of the -d option.
-jdomain
Joins the Samba server to a Windows NT domain as a domain member server. The domain
argument is the NetBIOS name of the Windows NT domain that is being joined. See also the -r and
-U options.
-m
Indicates that the account is a computer account in a Windows NT domain rather than a domain
user account.
-n
Sets the user's password to a null password. For the user to authenticate, the parameter null
passwords=yes must exist in the [global] section of the Samba configuration file.
-Rresolve_order_list
Sets the resolve order of the name servers. This option is similar to the resolveorder
configuration option and can take any of the four parameters lmhosts,host,wins, and bcast, in
any order. If more than one is specified, the argument is specified as a space-separated list.
-wpassword
For use when Samba has been compiled with the --with-ldapsam configure option. Specifies the
password that goes with the value of the ldap admin dn Samba configuration file parameter.
-xusername
Table of Contents
Deletes the user from the smbpasswd file. This is a one-way operation, and all information
Index
associated
with the entry is lost. To disable the account without deleting the user's entry in the file,
see the Reviews
-d option.
Reader Reviews
Errata
Other options
-cfilename
Publisher: O'Reilly
the 2003
Samba configuration file, overriding the compiled-in default.
PubSpecifies
Date: February
-Ddebug_level
ISBN: 0-596-00256-4
Pages: 556
Sets the debug (also called logging) level. The level can range from to 10. Debug level 0 logs only
Slots: 1
the
most important messages; level 1 is normal; levels 3 and above are primarily for debugging
and slow the program considerably.
-h
Using Prints
Samba,
command-line
Second Edition
usage
is a information.
comprehensive guide to Samba administration. This new edition covers
-L
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Causes
to rundomain
in local controller
mode, in which
ordinary
users are
allowed
to use the
Samba's
newsmbpasswd
role as a primary
and domain
member
server,
its support
for superuserthe use of
only
options.
This
requires
that
the
smbpasswd
file
be
made
readable
and
writable
by
the user.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
for testing
sharedThis
filesisand
printerspurposes.
from Unix clients.
-rNetBIOS_name
Specifies on which machine the password should change. If changing a Windows NT domain
password, the remote system specified by NetBIOS_name must be the PDC for the domain. The
user's username on the local system is used by default. See also the -U option for use when the
user's Samba username is different from the local username.
-Rresolve_order
Sets the resolve order of the name servers. This option is similar to the resolve order configuration
option and can take any of the four parameters lmhosts,host,wins, and bcast, in any order. If
more than one is specified, the argument is specified as a space-separated list.
-susername
Causessmbpasswd not to prompt for passwords from /dev/tty, but instead to read the old and new
passwords from the standard input. This is useful when calling smbpasswd from a script.
-S
Queries the domain controller of the domain, as specified by the workgroup parameter in the
Samba configuration file, and retrieves the domain's SID. This will then be used as the SID for the
local system. A specific PDC can be selected by combining this option with the -r option, and its
domain's SID will be used. This option is for migrating domain accounts from a Windows NT
primary domain controller to a Samba PDC.
-Uusername[%password]
Changes the password for username on the remote system. This is to handle instances in which the
remote username and local username are different. This option requires that -r also be used. Often
used with -j to provide the username of the administrative user on the primary domain controller
for adding computer accounts.
smbsh
Thesmbsh program allows SMB shares to be accessed from a Unix system. When smbsh is run, an extra
directory tree called /smbbecomes available to dynamically linked shell commands. The first level of
directories under
represent available workgroups, the next level of subdirectories represent the
Table/smb
of Contents
SMB servers in
each workgroup, and the third level of subdirectories represent the disk and printer
Index
shares
of eachReviews
server.
Reader Reviews
Errata
Options
Publisher: O'Reilly
-ddebug_level
Pub Date: February 2003
Sets
ISBN: the
0-596-00256-4
debug (sometimes called logging) level. The level can range from 0, the default, to 10.
0 logs only the most important messages; level 1 is normal; levels 3 and above are
primarily
for
debugging and slow smbsh considerably.
Slots: 1
-lfilename
Debug556
level
Pages:
Sets the name of the logging file. By default, messages are sent to stderr.
-Ldirectory
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
of Samba
from 2.0
to 2.2, including
selectedoverriding
features from
an alpha version
of 3.0, as well as
Specifies
the location
of smbsh's
shared libraries,
the compiled-in
default.
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also explores
-P prefix
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
and filesystem
the host Unix
system,isand
accessing
SetsNT/2000/XP
the name ofauthentication
the root directory
to use for security
the SMBon
filesystem.
The default
/smb.
shared
files and printers from Unix clients.
-R
resolve_order
Sets the resolve order of the name servers. This option is similar to the resolveorder
configuration option and can take any of the four parameters lmhosts,host,wins, and bcast, in
any order. If more than one is specified, the argument is specified as a space-separated list.
-Uusername
Provides the username, and optionally the password, for authenticating the connection to the SMB
server. The password can be supplied using the username%password format. If either or both the
username and password are not provided, smbsh will prompt interactively for them.
-W workgroup
Specifies the NetBIOS workgroup or domain to which the client will connect. This overrides the
workgroup parameter in the Samba configuration file and is sometimes necessary to connect to
some servers.
smbspool
Table of Contents
Samba printers
as well.
Index
Reviews
Reader Reviews
Command
synopsis
Errata
Using Samba, 2nd Edition
smbspool
job user title copies options filename
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
The arguments for smbspool, as shown here, are those used in the CUPS printing system. However,
Publisher: O'Reilly
some
of the arguments are currently ignored because they don't correspond to the Samba printing
Pub Date:
February
2003
system.
These
arguments
must be supplied in the command and can be filled in with "dummy" values.
ISBN: 0-596-00256-4
Thejob
argument
refers to the job number and is currently ignored. The user argument is the name of
Pages:
556
the user
who
submitted
the print job and is also ignored. The title argument is the name of the print
Slots: 1
job and must be supplied. It is used as the name of the remote print file. The copies argument is the
number of copies that will be printed. This number is used only if the (optional) filename argument is
supplied. Otherwise, only one copy is printed. The options argument, for specifying printing options, is
ignored.
The filename
argument
used for specifying
name of
the file to be printed.
Ifedition
it is notcovers
Using Samba,
Second Edition
is a is
comprehensive
guidethe
to Samba
administration.
This new
provided,
the
standard
input
will
be
used.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
The
printer
that
the
is to be domain
sent to controller
is specifiedand
in the
DEVICE_URI
variable.
format
Samba's
new
role
asjob
a primary
domain
member environment
server, its support
for The
the use
of
for
the
printer
name
is
a
device
Universal
Resource
Indicator,
which
can
be
in
any
of
the
following
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
formats:
shared files and printers from Unix clients.
smb://server/printer
smb://workgroup/server/printer
smb://username:password@server/printer
smb://username:password@workgroup/server/printer
smbstatus
Table of Contents
Options
Index
Reviews
-b
Reader Reviews
Errata
Causes2nd
smbstatus
Using Samba,
Edition
to produce brief output. This includes the version of Samba and auditing
information about the users that are connected to the server.
-d
Publisher:
GivesO'Reilly
verbose
output, which includes a list of services, a list of locked files, and memory usage
default.
Pubstatistics.
Date: February
2003
This
is the
-L
ISBN: 0-596-00256-4
Pages: 556
-p
Slots: 1
smbtar
Thesmbtar program is a shell-script wrapper around smbclient for doing tar-format archiving operations.
It is functionally very similar to the Unix tar program.
Table of Contents
Index
Command
synopsis
Reviews
Reader Reviews
smbtar
[options]
Errata
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Options
-a
Publisher: O'Reilly
Pub Date: February 2003
Resets
(clears) the archive attribute on files after they are backed up. The default is to leave the
ISBN: 0-596-00256-4
archive attribute unchanged.
Pages: 556
-bblocksize
Slots: 1
Sets block size, in units of 512 bytes, for reading or writing the archive file. Defaults to 20, which
results in a block size of 10240 bytes.
-ddirectory
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions
Changes
of Samba
the working
from 2.0
directory
to 2.2,on
including
the remote
selected
system
features
to directory
from an before
alpha version
startingof
the
3.0,
restore
as well
or as
the SWAT
graphical
configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
backup
operation.
Samba's new role as a primary domain controller and domain member server, its support for the use of
-i
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
mode;
are backed up only if they have the DOS archive attribute set.
sharedSpecifies
files andincremental
printers from
Unix files
clients.
The archive attribute is reset (cleared) after each file is read.
-llog_level
Sets the logging level. This corresponds to the -d option of smbclient and other Samba programs.
-Nfilename
Backs up only files newer than filename. For incremental backups.
-ppassword
Specifies the password to use to access a share. An alternative to using the username%password
format with the -u option.
-r
Restores files to the share from the tar file.
-sserver
Specifies the SMB server. See also the -x option.
-tfilename
Specifies the file or Unix device to use as the archiving medium. The default is tar.out or the value
of the TAPE environment variable, if it has been set.
-uusername
Specifies the user account to use when connecting to the share. You can specify the password as
well, in the format username%password. The username defaults to the user's Unix username.
-v
Operates in verbose mode, printing error messages and additional information that can be used in
debugging and monitoring. Backup and restore operations will list each file as it is processed.
-xshare
States the name of the share on the server to which to connect. The default is backup. See also the
-s option.
-Xfile_list
Tellssmbtar to exclude the specified files from the backup or restore operation.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
smbumount
Table of Contents
Index
Command
synopsis
Reviews
Reader Reviews
smbumount
mount_point
Errata
Using Samba, 2nd Edition
For ordinary users to issue the command, smbumount must be made suid root.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
testparm
Table of Contents
Command
Index
synopsis
Reviews
Reader Reviews
testparm
[options]
[filename] [hostname IP_addr]
Errata
If theSamba,
configuration
file is not provided using the filename argument, then it defaults to
Using
2nd Edition
/usr/local/samba/lib/smb.conf
. If the hostname and an IP address of a system are included, an extra
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
check is made to ensure that the system is allowed to connect to each service defined in the
configuration file. This is done by comparing the hostname and IP address to the definitions of the hosts
Publisher:
O'Reilly deny parameters.
allow
and hosts
Pub Date: February 2003
ISBN: 0-596-00256-4
Options
Pages: 556
Slots: 1
-h
Prints usage information for the program.
-L
server_name
Using
Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Setsgraphical
the %L configuration
variable
to the specified
server
name.
the SWAT
configuration
tool. Updated
for Windows
2000,
ME, and XP, the book also explores
-s
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
defaultfrom
behavior
of prompting for the Enter key to be pressed before printing the list of
sharedDisables
files andthe
printers
Unix clients.
configuration options for the server.
testprns
This is a very simple program that checks to see if a specified printer name exists in the system printer
capabilities (printcap) file.
Table of Contents
Index
Command
synopsis
Reviews
Reader Reviews
testprns
printername
Errata
[printcapname]
Using Samba, 2nd Edition
If
printcapname isn't specified, Samba attempts to use the one specified in the Samba configuration file
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
with the printcap name parameter. If none is specified there, Samba will try /etc/printcap.
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
wbinfo
This program retrieves and prints information from the winbindd daemon, which must be running for
wbinfo to function.
Table of Contents
Index
Command
synopsis
Reviews
Reader Reviews
wbinfo
[options]
Errata
Using Samba, 2nd Edition
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Options
-u
Publisher: O'Reilly
Pub Date: February 2003
Prints
all usernames that have been mapped from the Windows NT domain to Unix users. Users in
ISBN: 0-596-00256-4
all trusted domains are also listed.
-g
Pages: 556
Slots: 1
Prints all group names that have been mapped from the Windows NT domain to Unix groups.
Groups in all trusted domains are also reported.
-hNetBIOS_name
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Queries
WINS
server
and
prints
the IPselected
address features
of the specified
all versions
of the
Samba
from
2.0 to
2.2,
including
from ansystem.
alpha version of 3.0, as well as
-n
thename
SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Prints
the SID corresponding
thefilesystem
name specified.
The
can be
specified
DOMAIN/name
Windows
NT/2000/XP
authenticationtoand
security
onargument
the host Unix
system,
andas
accessing
(or
by
using
a
character
other
than
the
slash,
as
defined
by
the
winbind
separator
character)
to
shared files and printers from Unix clients.
specify both the domain and the name. If the domain and separator are omitted, the value of the
workgroup parameter in the Samba configuration file is used as the name of the domain.
-sSID
Prints the name mapped to a SID, which is specified in the format S-1-N-N-D-D-D-R.
-UUID
Prints the SID mapped to a Unix UID, if one exists in the current domain.
-Ggid
Prints the SID mapped to a Unix group ID, if one exists in the current domain.
-SSID
Prints the Unix UID that winbind has mapped to the specified SID, if one exists.
-YSID
Prints the Unix group ID that winbind has mapped to the specified SID, if one exists.
-t
Tests to see that the workstation trust account for the Samba server is valid.
-m
Prints a list of Windows NT domains trusted by the Windows server. This does not include the PDC's
domain.
-rusername
Prints the list of Unix group IDs to which the user belongs. This works only if the user's account is
maintained on a domain controller.
-ausername%password
Checks to see if a user can authenticate through winbindd using the specified username and
password.
-Ausername%password
Saves the username and password used by winbindd to the domain controller. For use when
operating in a Windows 2000 domain.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
and features, maybe for research and testing purposes, or just to see what the Samba developers have
Index
been up to lately.
Reviews
Reader
Reviews
The Samba team
keeps
the latest updates of the Samba source code in a Concurrent Versions System
Errata
(CVS) repository. CVS is a freely available configuration management tool and is distributed under the
Using
Samba, 2nd
Edition
GNU General
Public
License. You can download the latest copy from http://www.cvshome.org/. The
Samba
team
describes
various
ways
to access its CVS repository at
ByDavid Collier-Brown, Robert
Eckstein
, Jay Ts
http://www.samba.org/samba/cvs.html.
Publisher: O'Reilly
Pub Date: February 2003
Although the CVS code contains the latest features, it also contains the latest bugs
and sometimes won't even compile properly! If you prefer a less "bleeding edge"
Pages: 556 release, try looking in the alpha and pre directories on the Samba FTP server. The
Slots: 1
alpha directory contains alpha releases, and the pre directory contains (usually
more stable) prerelease versions. (See Chapter 2 for information on downloading
via FTP.) Alpha releases might be a little behind the latest CVS code, but are less
buggy and usually compile properly on the more common Unix versions.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of Samba
from
2.0 CVS
to 2.2,
including
selected
from an
alpha
version
3.0, as
well as
One
of the nicest
things
about
is its
ability to
handle features
remote logins.
This
means
thatof
people
across
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
the globe on the Internet can download and update various source files for any project that uses a CVS
Samba's new
roleisas
a primary
controller
and
domain
member on
server,
support
formust
the use
repository.
Such
the
case withdomain
Samba.
Once you
have
CVS installed
your its
system,
you
first of
log
Windows
NT/2000/XP
and
filesystem
security on the host Unix system, and accessing
in
to the Samba
sourceauthentication
server with the
following
command:
shared files and printers from Unix clients.
$cvs -d :pserver:[email protected]:/cvsroot login
ISBN: 0-596-00256-4
When you are prompted for a password, enter cvs. You are connected to the CVS server at
pserver.samba.org. Once you are connected, you can download the latest source tree with the following
command:[1]
[1]
The -z option causes the transfer to be made in GNU gzip compressed format and requires the gzip program to be
installed on your system to work. If you do not have gzip, omit the -z option.
Table of Contents
configure options:
Index
#./configureReviews
--with-smbmount --with-configdir=/etc/samba --with-manpages-langs=ja
Reader Reviews
configuration
fileEdition
in /etc/samba (instead of the default location of /usr/local/samba/lib ), and install
Using
Samba, 2nd
Japanese-language
manual pages. We have picked these three configure options because they illustrate
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
the usage of the three types of options that are included up to Samba 3.0. The --with-smbmount option
is a Boolean option, which can take a value of yes or no. All the Boolean options are set to no by default,
O'Reilly
andPublisher:
it is only
necessary to provide the option to turn it on. If you want to be more explicit, you can
Pub
Date:
February
2003
specify--with-smbmount=yes.
To turn an option off explicitly, you can also specify --without-feature
ISBN:
0-596-00256-4
rather than --with-feature=no.
Pages: 556
In the Slots:
case 1of the other two options we have shown, an argument must be supplied after the equals (=)
sign. Some of the options are used to specify the directories that Samba uses for various purposes. Only
one option is in the last group, where something other than a directory is specified as an option
argument.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
The supported configure options vary from release to release. For example, between Samba 2.2.x and
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
Samba 3.0, many options were dropped, and a few were added. To get a list of the configure options for
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
your release, use the following command:
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
#./configure
--helpauthentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table E-1 lists Samba's configure options.
Description
--with-acl-support
--with-afs
--with-automount
--with-codepagedir=dir
--with-configdir=dir
--with-dce-dfs
Support DCE/DFS
--with-fhs
--with-included-popt
--with-krb4=base-dir
Support Kerberos 4
--with-krb5=base-dir
--with-ldapsam
--with-libiconv=directory
Specifyiconv library
--with-libsmbclient
--with-lockdir=directory
--with-logfilebase=directory
--with-manpages-langs=language
--with-msdfs
--with-nisplus-home
--with-nisplussam
Table of Contents
Index
Reviews
--with-pam
--with-pam_smbpass
Reader Reviews
Errata
--with-piddir=directory
--with-privatedir=directory
By
David Collier-Brown, Robert Eckstein, Jay Ts
--with-profiling-data
Publisher: O'Reilly
--with-quotas
Pub Date: February
2003
ISBN: 0-596-00256-4
--with-readline=directory
Pages: 556
--with-sendfile-support
Slots: 1
--with-smbmount
--with-smbwrapper
Using
Samba, Second Edition is a comprehensive
guide to instead
Samba of
administration.
This new edition covers
--with-spinlocks
Use spinlocks
fcntl locks
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
--with-ssl
the
SWAT graphical configuration tool. Updated
Support
for Windows
SSL
2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
--with-sslinc=directory
Locationsecurity
of SSL include
files Unix system, and accessing
Windows
NT/2000/XP authentication and filesystem
on the host
shared
files and printers from Unix clients. Location of SSL libraries
--with-ssllib=directory
--with-swatdir=directory
--with-syslog
--with-tdbsam
--with-utmp
--with-winbind
Build winbind
--with-acl-support
Includes support for Windows NT/2000/XP access control lists (ACLs). For this to work, you need to
have POSIX ACL support in the host operating system. See Chapter 8 for details.
--with-afs
Includes support for the Andrew Filesystem (AFS), for authenticating users who are accessing files
through AFS.
--with-automount
Includes support for the automounter, a feature often used in conjunction with NFS, to mount NFS
shares automatically at the first attempt to access them. You might wish to enable this feature if
any of the directories shared by your Samba server are (or include) NFS-mounted directories.
--with-codepagedir=directory
Specifies the directory in which to put codepage files for internationalization support. See the
"Internationalization" section earlier in this chapter for more information on this feature. By default,
this directory is /usr/local/samba/lib/codepages .
--with-configdir=directory
Specifies the directory in which Samba keeps its configuration file, usually called smb.conf. By
default, this is /usr/local/samba/lib .
--with-dce-dfs
Includes support for the Distributed Computing Environment Distributed Filesystem (DCE/DFS).
This is a distributed filesystem included in some Unix variants and is not the same as Microsoft's
Distributed Filesystem (Dfs).
--with-fhs
Adheres to the Filesystem Hierarchy Standard when locating files. For details, see
http://www.pathname.com/fhs.
--with-included-popt
Table of Contents
Index
IncludesReviews
Samba's own support for parsing command-line options, instead of using the local
system's
popt(
) C-library function.
Reader Reviews
--with-krb4
=base-dir
Errata
Includes support for Kerberos Version 4.0, specifying the base directory of the Kerberos
protocol developed at MIT that uses private-key
cryptography to provide strong security between nodes. This version is not the same as Microsoft's
Publisher:
adaptation
O'Reillyof Kerberos in Active Directory, which is the preferred version for use with Samba. This
exists 2003
only in versions of Samba earlier than 3.0.
Puboption
Date: February
--with-krb5
=base-dir
ISBN: 0-596-00256-4
ByDaviddistribution.
Collier-BrownKerberos
, Robert Eckstein
Ts
is an,Jay
authentication
Pages: 556
Includes support for Kerberos Version 5.0, specifying the base directory of the Kerberos
Slots: 1
distribution. This version of Kerberos is compatible with the Kerberos authentication in Microsoft's
Active Directory used in Windows 2000 and Windows XP.
--with-ldapsam
Using Includes
Samba, Second
is aLDAP
comprehensive
guide
to Sambafile
administration.
This
new edition
covers
supportEdition
for using
instead of the
smbpasswd
for maintaining
Samba's
equivalent
all versions
to theof
Windows
Samba NT
from
SAM
2.0database.
to 2.2, including
This option
selected
is necessary
features to
from
usean
the
alpha
parameters
version ldap
of 3.0,
admin
as well
dn, as
the SWAT
ldapgraphical
filter,ldap
configuration
port,ldapserver,
tool. Updated
ldapssl,
forand
Windows
ldapsuffix
2000, in
ME,
the
and
Samba
XP, the
configuration
book also explores
file.
Samba's
It isnew
necessary
role as to
a primary
specify --with-ldapsam
domain controlleronly
and in
domain
Sambamember
versionsserver,
prior to
its3.0.
support for the use of
Windows NT/2000/XP
authentication and filesystem security on the host Unix system, and accessing
--with-libiconv
=directory
shared files and printers from Unix clients.
Specifies a location for iconv( ) support. The iconv( ) function exists in the C library to perform
conversion between different character sets. This option allows Samba's default method of
determining the location of the iconv( ) library to be overridden. Ordinarily, the configuration
process checks for support in the C library on the system and, if not found, uses code included in
the Samba source tree. Using --with-libiconv, it is possible to specify explicitly where the
support is located. The include files are assumed to be in directory/include, and library files are
assumed to be in directory/lib. This option is new in Samba 3.0.
--with-libsmbclient
Allows applications outside the Samba suite to access Samba's features. When --withlibsmbclient is specified, the library is built during the compilation process.
--with-lockdir=directory
Specifies the directory in which Samba keeps lock files. By default this directory is
/usr/local/samba/var/locks.
--with-logfilebase=directory
Specifies the directory in which Samba keeps log files for the smbd,nmbd, and winbindd daemons.
This defaults to /usr/local/samba/var.
--with-manpages-langs=language
Starting with Samba 3.0, Samba's manual pages are available in different languages. The default is
en for English, and the language can be specified as ja for Japanese or pl for Polish.
--with-msdfs
Includes support for Microsoft Distributed Filesystem (Dfs). See Chapter 8 for more information on
this feature. Specifying this option is necessary only in Samba versions prior to 3.0.
--with-nisplus-home
Includes support for locating the NIS+ server that is serving a particular user's home directory and
telling the client to connect to it. Use --with-automount along with this option.
--with-nisplussam
Includes support for integrating NIS+ into Samba's equivalent of the Windows NT password
database.
--with-pam
When this configure option is specified and the parameter obeypamrestrictions in the Samba
configuration file is set to yes, obeys PAM's configuration regarding account and session
management. When encrypted passwords are in use, Samba uses the smbpasswd file for
authentication,
bypassing the PAM subsystem. Therefore, this option works only when encrypt
Table of Contents
passwords
is set to no.
Index
--with-pam_smbpass
Reviews
Reader Reviews
When this
option is specified, the compilation process builds a PAM module called pam_smbpass.so
Errata
and
places
it in the source/bin directory. This module allows applications outside of the Samba suite
Using Samba, 2nd Edition
to authenticate users with Samba's smbpasswd file. For more information, see the README file in
ByDavidthe
Collier-Brown
, Robert Ecksteindirectory
, Jay Ts
source/pam_smbpass
of the Samba distribution and the file PAM-Authentication-AndSamba.html in the docs/html directory.
Publisher: O'Reilly
--with-piddir
=directory
Specifies
the directory in which Samba keeps files such as browse lists, WINS data, and PID files
ISBN: 0-596-00256-4
for
keeping
track of the process IDs of the Samba daemons. The default is
Pages: 556
/usr/local/samba/var/locks.
Slots: 1
--with-privatedir=directory
Specifies the directory in which Samba keeps the smbpasswd,secrets.tdb, and related files for
authentication. The default is /usr/local/samba/private.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
--with-profiling-data
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
tool.
Updated
for time
Windows
2000, ME,
and XP,
the
book
also explores
Includes
support
for analyzing
the
execution
of Samba's
internal
code.
This
is normally
used
Samba's
new
as a primary
domain controller and domain member server, its support for the use of
only
by role
the Samba
developers.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
--with-quotas
shared files and printers from Unix clients.
Includesdisk-quota support. This is classified as an experimental option by the Samba developers.
--with-readline=directory
Specifies a location for readline( ) support. The readline( ) function exists in the C library to accept
a line of input from an interactive user and provide support for editing and history. Samba uses
these functions in smbclient and rpcclient.
This option allows Samba's default method of determining the location of the readline( ) library to
be overridden. Ordinarily, the configuration process checks for support in the C library on the
system and, if not found, uses code included in the Samba source tree. Using --with-readline, it
is possible to specify the directory explicitly in which the library containing readline( ) is located.
--with-sendfile-support
Checks to see if the Samba host operating system supports the sendfile( ) system call, which
speeds up file transfers by copying data directly to and from kernel buffers, avoiding the overhead
of copying to and from buffers in user space. If the operating system has the sendfile( ) system
call, support is included in Samba for the usesendfile configuration file option. This is an
experimental option included in Samba 2.2.5 and later versions.
--with-smbmount
Must be specified if you want to mount SMB shares in your Unix filesystem using the smbfs
filesystem and the smbmount command, as discussed in Chapter 5. Currently, this works only with
Linux.
--with-smbwrapper
To use smbsh to access SMB shares from Unix (as discussed in Chapter 5), use this option to
include the smbwrapper library.
--with-spinlocks
Usesspin locks instead of the normal method of file locking that uses the fcntl( ) C-library function.
Using this option results in a Samba installation that consumes much more CPU time on the host
Index
=directory
Reviews
Specifies
the location
Reader
Reviews of the SSL libraries. The default location is /usr/local/ssl/lib. This option exists
in versions
prior to Samba 3.0.
Errata
--with-swatdir
=directory
Using
Samba, 2nd Edition
Specifies where to install the files for SWAT./usr/local/samba/swat is the default location.
--with-syslog
Publisher: O'Reilly
support
PubIncludes
Date: February
2003
for syslog error logging. This option must be specified for the Samba
configuration
file
parameters
syslog and syslogonly to work. This option is widely supported, but
ISBN: 0-596-00256-4
might
not
work
correctly
on
all
Samba host systems.
Pages: 556
--with-tdbsam
Slots: 1
Includes support for keeping Samba's equivalent of the Windows NT SAM in a .tdb database file
rather than in the smbpasswd file. This is an experimental feature.
--with-utmp
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
Includes
supportfrom
for user
accounting
in theselected
system's
utmp file.
It an
is necessary
for the
utmpasand
all versions
of Samba
2.0 to
2.2, including
features
from
alpha version
of 3.0,
well as
utmpgraphical
directory
Samba configuration
file options
to work.
ThisME,
option
widely
supported,
but
the SWAT
configuration
tool. Updated
for Windows
2000,
andis
XP,
the book
also explores
Samba's
might
newnot
role
work
as acorrectly
primary on
domain
all Samba
controller
host and
systems.
domain member server, its support for the use of
--with-winbind
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Includeswinbind support in Samba. Instead of defaulting to no, as with other boolean options, -with-winbind is automatically set to yes on systems that support winbind functionality. The only
time you would need to specify this option is to turn it off, like this:
#configure --without-winbind
This excludes winbind functionality from Samba even when the local operating system can support it. For
more information on winbind, see Chapter 9.
Tableisofan
Contents
administrative
tools
and
server software. One area in which it differs from Mac OS X is in the
Index
configuration
of
Samba-based
services. In this appendix, we'll tell you how to set up SMB file and printer
Reviews
shares,
enable
client
user
access,
and monitor activity. Our specific focus is on Mac OS X Server 10.2.
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table ofand
Contents
Directory Assistant,
Reviews
Reader Reviews
Errata
addition
Using Samba, 2nd In
Edition
For2003
more
Pub Date: February
as a PDF
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Briefly, the procedure for setting up SMB file and printer shares is as follows:
1. Designate share points in Workgroup Manager for file sharing.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all2.versions
Samba
from
to 2.2,
including
selected
features
from
an alpha
version
of 3.0, as well as
Set upof
print
queues
in2.0
Server
Settings
for printer
sharing,
and
activate
Printer
Service.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
new role
a primary
domain
controller
and domain
member server, its support for the use of
3. Configure
andasactivate
Windows
Services
in Server
Settings.
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
4. Activate
files and
Password
printersServer
from Unix
and clients.
enable SMB authentication in Open Directory Assistant.
5. Enable Password Server authentication for user accounts in Workgroup Manager.
6. Monitor file and print services with Server Status.
Figure F-1. Workgroup Manager: Share Points and Windows File Settings
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
F.1.2Slots:
Sharing
1
Printers
Printer shares are set up differently. First, launch Server Settings; under the File & Print tab, select Print,
then Configure Print Service.... Check the box labeled Automatically share new queues for Windows
Using Samba,
printing.
Next,Second
click theEdition
Print icon
is a comprehensive
again and then Show
guide Print
to Samba
Monitor.
administration.
Make sure the
This
printers
new edition
you want
covers
to
all versions
share
are listed.
of Samba
Printers
from
directly
2.0 toattached
2.2, including
to theselected
server should
features
have
from
queues
an alpha
created
version
automatically,
of 3.0, as well
but as
the SWAT
remote
printers
graphical
you configuration
wish to reshare
tool.
must
Updated
be added
for Windows
by clicking
2000,
NewME,
Queue
andand
XP, discovering
the book also
or explores
specifying
Samba's
the
printers.
newWhen
role as
you're
a primary
finished,
domain
clickcontroller
Save, select
andthe
domain
Print member
icon one server,
more time,
its support
and select
for the
Start
use
Print
of
WindowsSee
Service.
NT/2000/XP
Figure F-2.
authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Server Settings will make local printers available for sharing only if they're
PostScript compatible. Unfortunately, many printers, including consumer-grade
USB inkjet printers, aren't. If you want to make one of these printers available to
SMB clients, you can still add the share to /etc/smb.conf yourself with a text editor.
See "Rolling Your Own" later in this chapter for instructions and caveats related to
making manual changes to smb.conf.
Table of Figure
Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
The
Windows
Services
Access
tab offers
options to enable guest access and limit the number of
shared
files and
printers
from Unix
clients.
simultaneous client connections; under the Logging tab, you can specify the verbosity of your logging.
With options under the Neighborhood tab, you can configure your machine as a WINS client or server or
have it provide browser services locally or across subnets.
Password Server
Password Server is a feature introduced with Mac OS X Server 10.2. In prior versions of Mac
OS X Server, Windows authentication was handled with Authentication Manager, which stored
a user's Windows password in the tim_password property of the user's NetInfo record. This
can still be done in Version 10.2, although it's strongly discouraged because the encrypted
password is visible to other users with access to the NetInfo domain and can potentially be
decrypted.
If you need to use Authentication Manager, use the following procedure to enable it:
1. On every machine hosting a domain that will bind into the NetInfo hierarchy, execute the
commandtim -init -autotag for each domain, where tag is the name of the
domain's database.
2. When prompted, provide a password to be used as the encryption key for the domain.
This key is used to decrypt the Windows passwords and is stored in an encrypted file
readable only by root, /var/db/netinfo/.tag.tim .
3. SetAUTHSERVER=-YES- in /etc/hostconfig.
4. Start Authentication Manager by invoking tim. This is also executed during the boot
sequence by the AuthServer startup item.
5.
4.
5. Reset the password of each user requiring SMB client access. In Mac OS X Server 10.2
or later, make sure the user is set up for Basic authentication, not Password Server
authentication.
When you've finished configuring Windows Services, click the Save button, then click the Windows icon in
Server Settings, and select Start Windows Services. This starts the Samba daemons, enabling access
from SMB clients.
Table of Contents
Index
F.1.4
Activating
Password Server
Reviews
Reader Reviews
Now
that you've
set up file and printer shares, you need to make sure users can properly authenticate to
Errata
access
them.
In
Mac
OS X Server, this is accomplished with the Open Directory Password Server, a
Using Samba, 2nd Edition
service based on the Simple Authentication and Security Layer (SASL) standard and usable with many
By
David Collier-Brown
, Robert
Eckstein, Jay
Ts
different
authentication
protocols,
including
the LAN Manager and Windows NT LAN Manager (NTLM)
protocols. This section describes how to support SMB client authentication, but for more information on
Publisher:
O'Reilly
what
Password
Server does and how it works, see the Mac OS X Server Administrator's Guide.
Pub Date: February 2003
To enable
Server or merely check its settings, start the Open Directory Assistant. Unless you
ISBN:Password
0-596-00256-4
wish to change any of the settings, just click the right arrow button in the lower-right corner of the
Pages: 556
window until you get to the first Security step. At this point, activate Password Server by selecting the
Slots: 1
option marked Password and authentication information will be provided to other systems. The next step
displays the main administrative account, and the one after that gives you a choice of authentication
protocols to enable (see Figure F-4). Make sure that SMB-NT is checked, and check SMB-Lan Manager if
you have Windows 95/98/Me or older clients. The final step saves the Password Server configuration and
Using
Samba,
prompts
you toSecond
reboot.Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Figure F-4. Password Server authentication protocols
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
F.1.6
Monitoring
Services
Using Samba,
Second Edition
is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT
graphical
configuration
tool.you'll
Updated
2000,
andThe
XP,Server
the book
also application
explores
Once
you've
got everything
working,
wantfor
to Windows
keep an eye
on ME,
things.
Status
Samba's
role
as the
a primary
controller
domain
member
its support
for the
use
of
gives
younew
views
into
variousdomain
services
providedand
by Mac
OS X
Server.server,
For Windows
Services,
you
can
Windows
NT/2000/XP
authentication
and filesystem
Unix system, and accessing
see
the current
state of
the service, browse
the logs security
(locatedon
in the host
directory
shared files and printers from Unix
clients.
/Library/Logs/WindowsServices),
display
and terminate individual connections, and view a graph of
connections over time (see Figure F-6). Similar information is provided for Print Service.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
of Contents
Index
Instead,
a process
named sambadmind generates /etc/smb.conf from the configuration specified in
Reviews
Server
Settings
and
Workgroup Manager and handles starting and restarting the Samba daemons as
Reader Reviews
necessary. The sambadmind process is in turn monitored by watchdog, which keeps an eye on certain
Errata
processes and restarts those which fail. The watchdog utility is configured in /etc/watchdog.conf, a file
Using Samba, 2nd Edition
similar to a System V inittab, which specifies how the services under watchdog's purview are to be
By
David Collier-Brown
, Robert
Ts
treated.
For example,
the Eckstein
line for,Jay
sambadmind
looks like this:
sambadmin:respawn:/usr/sbin/sambadmind
-d
Publisher: O'Reilly
Using a watchdog-monitored process such as sambadmind to start the Samba daemons, instead of a
ISBN: 0-596-00256-4
one-time execution of a startup item, results in more reliable service. In Mac OS X Server, if a Samba
Pages: 556
daemon dies unexpectedly, it is quickly restarted. (Examples of other services monitored by watchdog
Slots: 1 Server, Print Service, and the Server Settings daemon that allows remote management.)
are Password
There's another wrinkle in Mac OS X Server: the Samba configuration settings are not written directly to
/etc/smb.conf, as they are in the non-Server version of Mac OS X. Instead, they're stored in the server's
local
Directory
from
which sambadmind
them and regenerates
smb.conf.
For
UsingOpen
Samba,
Seconddomain,
Edition[1]
is a
comprehensive
guide toretrieves
Samba administration.
This new
edition covers
example,
the
parameters
are stored
in /config/SMBServer
(see
Figure
F-7).ofShare
point
all versions
ofSamba
Sambaglobal
from 2.0
to 2.2, including
selected
features from an
alpha
version
3.0, as
well as
information
is also kept
in Open Directory,
underfor
/config/SharePoints,
takes
the SWAT graphical
configuration
tool. Updated
Windows 2000, ME,while
and CUPS
XP, the
bookresponsibility
also exploresfor
printer
configuration
in
/etc/cups/printers.conf
(also
creating
stub
entries
used
by
Samba
Samba's new role as a primary domain controller and domain member server, its support in
for the use of
/etc/printcap).
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
[1]
In versions of Mac OS X prior to 10.2, Open Directory domains were called NetInfo domains. NetInfo Manager
(located in /Applications/Utilities) provides a graphical interface to view and modify the contents of Open Directory
databases. For more information, see the Mac OS X Server Administrator's Guide , as well as Understanding and Using
NetInfo, downloadable from the Mac OS X Server resources web page at http://www.apple.com/server/resources.html.
Table of Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all
versions
of Samba from
2.0 to 2.2, of
including
selected
features
from
an Server
alpha version
ofapplication,
3.0, as well as
Table
F-1 summarizes
the association
Windows
Services
settings
in the
Settings
the
SWAT
graphical
configuration
tool.
Updated
for
Windows
2000,
ME,
and
XP,
the
book
also
explores
properties stored in Open Directory, and parameters in /etc/smb.conf.
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
General
Server Name
netbios_name
netbios name
General
Workgroup
workgroup
workgroup
General
Description
description
server string
General
Code Page
code_page
General
Start Windows Services on
auto_start
system startup
N/A
Access
guest_access,map_to_guest
map to guest
N/A
guest_account
guest account
Access
Maximum client
connections
max_connections
Logging
logging
log level
WINS_enabled,WINS_register
wins support
Neighborhood
WINS Registration
Enable WINS server
WINS_enabled
wins support
Neighborhood
WINS Registration
Register with WINS server
WINS_register,WINS_address
wins server
Detail Level
Neighborhood
Off
WINS Registration
Neighborhood
Workgroup/Domain
Services
Master Browser
Local_Master
local master
Neighborhood
Workgroup/Domain
Services
Domain Master Browser
Domain_Master
domain master
printing
N/A
lprm_command
lprm command
lppause_command
lppause command
lpresume_command
lpresume command
printer_admin
printer admin
encryption
encrypt passwords
By
N/A
David Collier-Brown, Robert Eckstein, Jay Ts
coding_system
coding system
log_dir
N/A
smb_log
log file
nmb_log
N/A
samba_sbindir
N/A
N/A
samba_bindir
N/A
N/A
samba_libdir
N/A
N/A
N/A
Table of Contents
Index
Reviews
N/A
Reader Reviews
Errata
N/A
N/A
Publisher: O'Reilly
N/A
Pub Date: February
N/A
2003
ISBN: 0-596-00256-4
Pages: 556
N/A
Slots: 1
Using
guide to Samba administration.
samba_lockdir
N/A Samba, Second Edition is a comprehensive
N/A This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
samba_vardir
the
N/ASWAT graphical configuration tool. Updated
for Windows 2000, ME, and XP,
N/Athe book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
stop_time
N/A
Windows
NT/2000/XP authentication and filesystem security on the host UnixN/A
system, and accessing
shared files and printers from Unix clients.
Index
Reader Reviews
From that point on, the GUI will be useful only for starting, stopping, and monitoring the servicenot for
Reviews
configuring it.
Errataown version of Samba, you can still manage it from Server Settings by changing some
If you install your
Using
Edition properties
of theSamba,
Open 2nd
Directory
in /config/SMBServer.
To do this, open NetInfo Manager and modify the samba_sbindir and samba_bindir properties to match
the location of your Samba installation. Optionally, you can modify samba_libdir,samba_vardir, and
Publisher: O'Reilly
samba_lockdir. Assuming a default Samba installation, you can also change these at the command line
Pub Date: February 2003
with the following commands:
ISBN: 0-596-00256-4
556
#niclPages:
. -create
Slots: 1
Section G.1.
GNU
Free Documentation License
Table of
Contents
Index
Reviews
Reader Reviews
Errata
Publisher: O'Reilly
Pub Date: February 2003
ISBN: 0-596-00256-4
Pages: 556
Slots: 1
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared files and printers from Unix clients.
Table of Contents
Reviews
Reader Reviews
Copyright
2000,
Errata
Everyone is permitted
to copy and distribute verbatim copies of this license document, but changing it is
Using
Samba, 2nd Edition
not allowed.
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
Publisher: O'Reilly
0. PREAMBLE
Pub Date: February 2003
ISBN: 0-596-00256-4
The purpose
of this License is to make a manual, textbook, or other functional and useful document
"free" Pages:
in the556
sense of freedom: to assure everyone the effective freedom to copy and redistribute it, with
or without
it, either commercially or noncommercially. Secondarily, this License preserves for
Slots:modifying
1
the author and publisher a way to get credit for their work, while not being considered responsible for
modifications made by others.
This License is a kind of "copyleft", which means that derivative works of the document must themselves
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
be free in the same sense. It complements the GNU General Public License, which is a copyleft license
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
designed for free software.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's
role as
a primary
domain
and
domainfor
member
server, its
support
forsoftware
the use of
We have new
designed
this
License in
order controller
to use it for
manuals
free software,
because
free
Windows
NT/2000/XP
authentication
and
filesystem
security
on
the
host
Unix
system,
and
accessing
needs free documentation: a free program should come with manuals providing the same freedoms that
shared
files and
printers
from
Unix clients.
the software
does.
But this
License
is not limited to software manuals; it can be used for any textual
work, regardless of subject matter or whether it is published as a printed book. We recommend this
License principally for works whose purpose is instruction or reference.
Texts, in the notice that says that the Document is released under this License. A Front-Cover Text may
be at most 5 words, and a Back-Cover Text may be at most 25 words.
A "Transparent" copy of the Document means a machine-readable copy, represented in a format whose
specification is available to the general public, that is suitable for revising the document straightforwardly
with generic text editors or (for images composed of pixels) generic paint programs or (for drawings)
some widely available drawing editor, and that is suitable for input to text formatters or for automatic
translation to a variety of formats suitable for input to text formatters. A copy made in an otherwise
Transparent file format whose markup, or absence of markup, has been arranged to thwart or discourage
Table of Contents
subsequent modification
by readers is not Transparent. An image format is not Transparent if used for
Index
any substantial
amount of text. A copy that is not "Transparent" is called "Opaque".
Reviews
Examples of suitable
formats for Transparent copies include plain ASCII without markup, TEXinfo input
Reader Reviews
A
E
format, L T X Errata
input format, SGML or XML using a publicly available DTD, and standard-conforming simple
HTML,Samba,
PostScript
or PDF designed for human modification. Examples of transparent image formats
Using
2nd Edition
include PNG, XCF and JPG. Opaque formats include proprietary formats that can be read and edited only
ByDavid Collier-Brown, Robert Eckstein, Jay Ts
by proprietary word processors, SGML or XML for which the DTD and/or processing tools are not
generally available, and the machine-generated HTML, PostScript or PDF produced by some word
Publisher: for
O'Reilly
processors
output purposes only.
Pub Date: February 2003
The "Title
Page"
means, for a printed book, the title page itself, plus such following pages as are needed
ISBN:
0-596-00256-4
to hold,
legibly,
Pages:
556 the material this License requires to appear in the title page. For works in formats which
do not have any title page as such, "Title Page" means the text near the most prominent appearance of
Slots: 1
the work's title, preceding the beginning of the body of the text.
A section "Entitled XYZ" means a named subunit of the Document whose title either is precisely XYZ or
contains XYZ in parentheses following text that translates XYZ in another language. (Here XYZ stands for
Using
Samba,
Second
is a comprehensive
to Samba administration.
This "Endorsements",
new edition covers
a specific
section
nameEdition
mentioned
below, such as guide
"Acknowledgments",
"Dedications",
all "History".)
versions of To
Samba
from the
2.0 Title"
to 2.2,
selected
features
from an
versionmeans
of 3.0,that
as well
as
or
"Preserve
ofincluding
such a section
when
you modify
thealpha
Document
it
the SWAT
configuration
tool. Updated
fordefinition.
Windows 2000, ME, and XP, the book also explores
remains
a graphical
section "Entitled
XYZ" according
to this
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XP
authentication
filesystem
security
the host
Unix
system,
andLicense
accessing
The
Document
may include
Warrantyand
Disclaimers
next
to theon
notice
which
states
that this
applies
shared
files and printers
from UnixDisclaimers
clients.
to
the Document.
These Warranty
are considered to be included by reference in this License,
but only as regards disclaiming warranties: any other implication that these Warranty Disclaimers may
have is void and has no effect on the meaning of this License.
2. VERBATIM COPYING
You may copy and distribute the Document in any medium, either commercially or noncommercially,
provided that this License, the copyright notices, and the license notice saying this License applies to the
Document are reproduced in all copies, and that you add no other conditions whatsoever to those of this
License. You may not use technical measures to obstruct or control the reading or further copying of the
copies you make or distribute. However, you may accept compensation in exchange for copies. If you
distribute a large enough number of copies you must also follow the conditions in section 3.
You may also lend copies, under the same conditions stated above, and you may publicly display copies.
3. COPYING IN QUANTITY
If you publish printed copies (or copies in media that commonly have printed covers) of the Document,
numbering more than 100, and the Document's license notice requires Cover Texts, you must enclose the
copies in covers that carry, clearly and legibly, all these Cover Texts: Front-Cover Texts on the front
cover, and Back-Cover Texts on the back cover. Both covers must also clearly and legibly identify you as
the publisher of these copies. The front cover must present the full title with all words of the title equally
prominent and visible. You may add other material on the covers in addition. Copying with changes
limited to the covers, as long as they preserve the title of the Document and satisfy these conditions, can
be treated as verbatim copying in other respects.
If the required texts for either cover are too voluminous to fit legibly, you should put the first ones listed
(as many as fit reasonably) on the actual cover, and continue the rest onto adjacent pages.
If you publish or distribute Opaque copies of the Document numbering more than 100, you must either
include a machine-readable Transparent copy along with each Opaque copy, or state in or with each
Opaque copy a computer-network location from which the general network-using public has access to
download using public-standard network protocols a complete Transparent copy of the Document, free of
added material. If you use the latter option, you must take reasonably prudent steps, when you begin
distribution of Opaque copies in quantity, to ensure that this Transparent copy will remain thus accessible
at the stated location until at least one year after the last time you distribute an Opaque copy (directly or
through your agents or retailers) of that edition to the public.
Table of Contents
Reader Reviews
Errata
It is requested, but not required, that you contact the authors of the Document well before redistributing
Index
any large number
of copies, to give them a chance to provide you with an updated version of the
Document. Reviews
4. MODIFICATIONS
You may copy and distribute a Modified Version of the Document under the conditions of sections 2 and 3
Publisher:
O'Reillythat you release the Modified Version under precisely this License, with the Modified
above,
provided
Pub Date:
February
2003of the Document, thus licensing distribution and modification of the Modified
Version
filling
the role
ISBN:
0-596-00256-4
Version
to whoever
possesses a copy of it. In addition, you must do these things in the Modified Version:
Pages: 556
Slots: 1
1. Use in the Title Page (and on the covers, if any) a title distinct from that of the Document, and from
those of previous versions (which should, if there were any, be listed in the History section of the
Document). You may use the same title as a previous version if the original publisher of that version
gives permission.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
all2.versions
Samba
from 2.0
to 2.2, including
selected
features
from an
alpha version
of 3.0, as of
well
as
List onof
the
Title Page,
as authors,
one or more
persons
or entities
responsible
for authorship
the
the SWAT
graphicalinconfiguration
Updated
for Windows
2000,
ME,
the book
alsoof
explores
modifications
the Modified tool.
Version,
together
with at least
five
of and
the XP,
principal
authors
the
Samba's
new role
asofa its
primary
domain
controller
and
domain
server,
itsrelease
supportyou
for from
the use
Document
(all
principal
authors,
if it has
fewer
thanmember
five), unless
they
thisof
Windows
NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
requirement.
shared files and printers from Unix clients.
3. State on the Title page the name of the publisher of the Modified Version, as the publisher.
4. Preserve all the copyright notices of the Document.
5. Add an appropriate copyright notice for your modifications adjacent to the other copyright notices.
6. Include, immediately after the copyright notices, a license notice giving the public permission to use
the Modified Version under the terms of this License, in the form shown in the Addendum below.
7. Preserve in that license notice the full lists of Invariant Sections and required Cover Texts given in
the Document's license notice.
8. Include an unaltered copy of this License.
9. Preserve the section Entitled "History", Preserve its Title, and add to it an item stating at least the
title, year, new authors, and publisher of the Modified Version as given on the Title Page. If there is
no section Entitled "History" in the Document, create one stating the title, year, authors, and
publisher of the Document as given on its Title Page, then add an item describing the Modified
Version as stated in the previous sentence.
10. Preserve the network location, if any, given in the Document for public access to a Transparent copy
of the Document, and likewise the network locations given in the Document for previous versions it
was based on. These may be placed in the "History" section. You may omit a network location for a
work that was published at least four years before the Document itself, or if the original publisher of
the version it refers to gives permission.
11. For any section Entitled "Acknowledgments" or "Dedications", Preserve the Title of the section, and
preserve in the section all the substance and tone of each of the contributor acknowledgments
and/or dedications given therein.
12. Preserve all the Invariant Sections of the Document, unaltered in their text and in their titles.
13.
12.
Section numbers or the equivalent are not considered part of the section titles.
13. Delete any section Entitled "Endorsements". Such a section may not be included in the Modified
Version.
14. Do not retitle any existing section to be Entitled "Endorsements" or to conflict in title with any
Invariant Section.
15. Preserve any Warranty Disclaimers.
Table of Contents
If the Modified
Index Version includes new front-matter sections or appendices that qualify as Secondary
SectionsReviews
and contain no material copied from the Document, you may at your option designate
some or all of these sections as invariant. To do this, add their titles to the list of Invariant Sections
Reader Reviews
in the Modified Version's license notice. These titles must be distinct from any other section titles.
Errata
You may add a section Entitled "Endorsements", provided it contains nothing but endorsements of
example, statements of peer review or that the text
has been approved by an organization as the authoritative definition of a standard.
ByDavid
Collier-Brown
Eckstein
, Jay Ts partiesfor
your
Modified,Robert
Version
by various
Publisher: O'Reilly
You may add a passage of up to five words as a Front-Cover Text, and a passage of up to 25 words
as a Back-Cover Text, to the end of the list of Cover Texts in the Modified Version. Only one passage
ISBN: 0-596-00256-4
of Front-Cover Text and one of Back-Cover Text may be added by (or through arrangements made
Pages:
556
by) any
one entity. If the Document already includes a cover text for the same cover, previously
Slots: 1by you or by arrangement made by the same entity you are acting on behalf of, you may not
added
add another; but you may replace the old one, on explicit permission from the previous publisher
that added the old one.
author(s)
andEdition
publisher(s)
of the Document
dotonot
by this
License give permission
to usecovers
their
UsingThe
Samba,
Second
is a comprehensive
guide
Samba
administration.
This new edition
names
for
publicity
for
or
to
assert
or
imply
endorsement
of
any
Modified
Version.
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well as
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows
NT/2000/XPDOCUMENTS
authentication and filesystem security on the host Unix system, and accessing
5.
COMBINING
shared files and printers from Unix clients.
You may combine the Document with other documents released under this License, under the terms
defined in section 4 above for modified versions, provided that you include in the combination all of the
Invariant Sections of all of the original documents, unmodified, and list them all as Invariant Sections of
your combined work in its license notice, and that you preserve all their Warranty Disclaimers.
The combined work need only contain one copy of this License, and multiple identical Invariant Sections
may be replaced with a single copy. If there are multiple Invariant Sections with the same name but
different contents, make the title of each such section unique by adding at the end of it, in parentheses,
the name of the original author or publisher of that section if known, or else a unique number. Make the
same adjustment to the section titles in the list of Invariant Sections in the license notice of the combined
work.
In the combination, you must combine any sections Entitled "History" in the various original documents,
forming one section Entitled "History"; likewise combine any sections Entitled "Acknowledgements", and
any sections Entitled "Dedications". You must delete all sections Entitled "Endorsements".
6. COLLECTIONS OF DOCUMENTS
You may make a collection consisting of the Document and other documents released under this License,
and replace the individual copies of this License in the various documents with a single copy that is
included in the collection, provided that you follow the rules of this License for verbatim copying of each
of the documents in all other respects.
You may extract a single document from such a collection, and distribute it individually under this
License, provided you insert a copy of this License into the extracted document, and follow this License in
all other respects regarding verbatim copying of that document.
Index
covers
that
bracket
the
Document within the aggregate, or the electronic equivalent of covers if the
Reviews
Document is in electronic form. Otherwise they must appear on printed covers that bracket the whole
Reader Reviews
aggregate.
Errata
8. TRANSLATION
Publisher: O'Reilly
Translation is considered a kind of modification, so you may distribute translations of the Document
Pub Date: February 2003
under the terms of section 4. Replacing Invariant Sections with translations requires special permission
ISBN: 0-596-00256-4
from their
copyright holders, but you may include translations of some or all Invariant Sections in
Pages:
556 original versions of these Invariant Sections. You may include a translation of this License,
addition to the
1
and allSlots:
the license
notices in the Document, and any Warranty Disclaimers, provided that you also include
the original English version of this License and the original versions of those notices and disclaimers. In
case of a disagreement between the translation and the original version of this License or a notice or
disclaimer, the original version will prevail.
Using Samba, Second Edition is a comprehensive guide to Samba administration. This new edition covers
If
section in
Document
is Entitled
"Acknowledgements",
"Dedications",
or "History",
requirement
all aversions
of the
Samba
from 2.0
to 2.2, including
selected features
from an alpha
version ofthe
3.0,
as well as
(section
4)
to
Preserve
its
Title
(section
1)
will
typically
require
changing
the
actual
title.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
shared
files and printers from Unix clients.
9.
TERMINATION
You may not copy, modify, sublicense, or distribute the Document except as expressly provided for under
this License. Any other attempt to copy, modify, sublicense or distribute the Document is void, and will
automatically terminate your rights under this License. However, parties who have received copies, or
rights, from you under this License will not have their licenses terminated so long as such parties remain
in full compliance.
Colophon
Our look is the result of reader comments, our own experimentation, and feedback from distribution
channels. Distinctive covers complement our distinctive approach to technical topics, breathing
personality and life into potentially dry subjects.
Our look is the result of reader comments, our own experimentation, and feedback from distribution
channels. Distinctive covers complement our distinctive approach to technical topics, breathing
Table of Contents
personality and life into potentially dry subjects.
Index
Reader
Reviews
This type of bird
is one
of 50 hornbill species. The African ground hornbill is a medium- to large-size bird
characterized Errata
by a bright red waddle under a very long beak, dark-colored body and wings, long
Using
Samba,and
2ndshort
Edition
eyelashes,
legs.
Like all hornbills, it has a casque, a large but lightweight growth on the top of
itsDavid
beak,
which grows
more
folds,Jay
as Ts
the bird ages. It is the only ground-dwelling species of hornbill,
By
Collier-Brown
, Robert
Eckstein
though it is able to fly when necessary. It lives in the grasslands of Southern and Eastern Africa and
nests
in the foliage of dense trees, not in nest holes in the ground as other hornbills do. Its diet includes
Publisher: O'Reilly
mostly fruit, as well as large insects and small mammals. The African ground hornbill is considered to be
Pub Date: February 2003
sacred by many Africans, and as such, this bird is part of many legends and superstitions.
ISBN: 0-596-00256-4
Pages:
Darren
Kelly556
was
the production editor, Jeffrey Holcomb was the copyeditor, and Audrey Doyle was the
proofreader
Slots: 1for Using Samba, Second Edition . Linley Dolby, Colleen Gorman, and Claire Cloutier provided
quality control. Reg Aubry, Phil Dangler, Genevieve d'Entremont, and Judy Hoer provided production
support. Julie Hawks wrote the index.
Edie
designed
the cover
of this book. The
cover
image isadministration.
a 19th-centuryThis
engraving
from covers
the
UsingFreedman
Samba, Second
Edition
is a comprehensive
guide
to Samba
new edition
Dover
Pictorial
Archive.
Emma
Colby
produced
the
cover
layout
with
QuarkXPress
4.1
using
Adobe's
ITC
all versions of Samba from 2.0 to 2.2, including selected features from an alpha version of 3.0, as well
as
Garamond
font.
the SWAT graphical configuration tool. Updated for Windows 2000, ME, and XP, the book also explores
Samba's new role as a primary domain controller and domain member server, its support for the use of
David Futato designed the interior layout. This book was converted by Mike Sierra to FrameMaker 5.5.6
Windows NT/2000/XP authentication and filesystem security on the host Unix system, and accessing
with a format conversion tool created by Erik Ray, Jason McIntosh, Neil Walls, and Mike Sierra that uses
shared files and printers from Unix clients.
Perl and XML technologies. The text font is Linotype Birka; the heading font is Adobe Myriad Condensed;
and the code font is LucasFont's TheSans Mono Condensed. The illustrations that appear in the book were
produced by Robert Romano and Jessamyn Read using Macromedia FreeHand 9 and Adobe Photoshop 6.
The tip and warning icons were drawn by Christopher Bing. This colophon was written by Nicole Arigo.
The online edition of this book was created by the Safari production group (John Chodacki, Becki Maisch,
and Madeleine Newell) using a set of Frame-to-XML conversion and cleanup tools written and maintained
by Erik Ray, Benn Salter, John Chodacki, and Jeff Liggett.